Government agencies publicly linked the WellMess malware to APT29, with the UK NCSC supported by CSE, NSA, and DHS CISA, while CISA also published malware analysis for the threat. WellMess is a cross-platform backdoor seen in Linux, Windows, and .NET variants that communicates over HTTP, sends command output in RSA-encrypted POST data, stores RC6-encrypted data in HTTP cookie headers, and supports shell command execution, file upload and download, and in some Windows samples, PowerShell execution.
Independent technical analysis said the public evidence did not conclusively prove a single actor was responsible. Researchers found infrastructure pivots from the domain onedrive-jp[.]com and IP addresses tied to a 2018 sample that suggested a possible connection to activity previously associated with APT28, while another sample, SangforUD.exe, showed weaker TTP overlap with activity attributed to DarkHotel. The conflicting indicators underscored that malware attribution can be distorted by shared code, overlapping infrastructure, or deliberate false flags, even as confirmed infections were reported in Japanese organizations.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos published an assessment saying open-source and technical evidence did not independently confirm or refute the government attribution of WellMess to APT29. The post highlighted weak alternative links to infrastructure associated with APT28 and to Sangfor/DarkHotel-related activity.
CISA released analysis report MAR-10296782-2.v1 covering WELLMESS. The report publicly documented the malware in mid-2020 amid broader scrutiny of its use.
A second WellMess sample with SHA-256 65495d173e305625696051944a36a031ea94bb3a4f13034d8be740982bc4ab75 and original name SangforUD.exe was submitted to VirusTotal. Talos notes this occurred before the related attack was publicly disclosed.
JPCERT/CC published analysis of WellMess as a cross-platform backdoor affecting Linux and Windows. The report said infections had been confirmed in Japanese organizations and listed observed command-and-control infrastructure and sample hashes.
A WellMess sample later identified by SHA-256 0b8e6a11adaa3df120ec15846bb966d674724b6b92eae34d63b665e0698e0193 was submitted to VirusTotal. The sample used 45.123.190[.]168 as its command-and-control server and had the original filename QnapSSL.
The domain my-iri[.]org pointed to 198.251.83[.]27 from April 13 to April 19, 2018. Talos cites Microsoft's prior association of my-iri[.]org with attacks on U.S. political institutions attributed to APT28.
The UK National Cyber Security Centre publicly attributed WellMess to APT29, with support from Canada's CSE, the U.S. NSA, and DHS CISA. Talos later cited this as the principal government attribution under debate.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourceus-cert.cisa.gov
Open sourceblogs.jpcert.or.jp
Open sourceblogs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.