Researchers attributed a new phishing campaign to GOFFEE, an APT group tracked since 2023, targeting mainly technology organizations in Russia and newly extending to Belarus. The attackers sent emails with intentionally corrupted-looking documents that pushed victims to enable content, triggering remote template injection, a staged payload chain, and final in-memory .NET execution. The operation relied on a mix of phishing and living-off-the-land techniques, with operators conducting manual post-exploitation and using legitimate tools to blend into victim environments.
Post-compromise activity included reconnaissance and theft of credentials and configuration data from software such as AnyDesk, OpenVPN, Kerio Control, Telegram, and pgAdmin, along with data exfiltration hidden in HTTP User-Agent headers. Investigators also observed GOFFEE bringing its own mshta.exe, establishing persistence through InstallUtil.exe and a malicious service disguised as ASUS software, and modifying pgAdmin source code to redirect communications to attacker-controlled infrastructure. In a notable escalation, researchers identified a Mythic agent running inside a Linux container, likely launched through a tampered RabbitMQ service script and executed filelessly with memfd_create, marking the group’s apparent move into containerized environments.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Kaspersky states it has tracked the GOFFEE APT group since 2023, establishing the start of the group's observed activity in this reporting context.
The Securelist report describes GOFFEE bringing its own mshta.exe, using InstallUtil.exe and a malicious service disguised as ASUS software for persistence, and modifying pgAdmin source code to redirect communications to attacker-controlled infrastructure.
Researchers found a GOFFEE Mythic agent running inside a Linux container, likely launched through a modified RabbitMQ service script and executed filelessly with memfd_create. The report presents this as an apparent expansion of GOFFEE activity into containerized environments.
The reporting highlights GOFFEE exfiltrating data through HTTP User-Agent headers as part of the observed campaign.
The attackers were observed relying heavily on legitimate tools and manual post-exploitation, including reconnaissance and harvesting credentials and configurations from software such as AnyDesk, OpenVPN, Kerio Control, Telegram, and pgAdmin.
The campaign uses phishing emails with corrupted-looking documents that prompt victims to enable content, triggering remote template injection and a multi-stage chain that ends with an in-memory .NET payload.
Researchers identified a newly observed phishing campaign attributed with high confidence to GOFFEE. The campaign primarily targets technology-sector organizations in Russia and newly includes organizations in Belarus.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 86 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.