WellMess is a cross-platform remote access trojan associated with Russian state-sponsored activity and publicly attributed by the United Kingdom, Canada, and the United States to APT29 in operations that included targeting COVID-19 vaccine development organizations. The malware has been observed in Golang variants for Windows and Linux, as well as a Windows .NET variant, enabling operators to reuse core functionality across platforms.
WellMess communicates with command-and-control infrastructure over HTTP and has also been reported using DNS and HTTPS in some variants. It supports remote command execution, including arbitrary shell commands, file upload and download, and exfiltration of host data. The Windows variant can execute PowerShell scripts received from command and control. WellMess also performs host reconnaissance by collecting information such as the current username, IP address, and domain context from infected systems and transmitting that information to operators.
Its communications include layered encoding and encryption. Reported behaviors include Base64-encoded command-and-control traffic, decryption and decoding of data received from the controller, and encryption of outbound HTTP POST data using RC6 together with a dynamically generated AES key protected by RSA. These features complicate network inspection and analysis while protecting tasking and exfiltrated data in transit.
WellMess has been deployed after initial compromise through exploitation of unpatched public-facing vulnerabilities rather than being tied to a single delivery mechanism. Following deployment, operators have used it as a foothold for post-compromise activity against high-value internal systems, including research repositories and directory infrastructure. The malware is notable both for its cross-platform design and for its role in espionage-oriented intrusions linked to APT29.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WellMess - Russian state-sponsored group APT29 deployed new upgraded versions of their Go-based WellMess malware last year.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
“…deployment of custom malware known as WellMess, WellMail, and Sorefang to target organizations involved in COVID-19 vaccine development.”
22 distinct techniques documented for this family, organized by ATT&CK tactic.
When a client connects to the malicious server, it automatically downloaded and executed the new trojanized version of the VPN client.
The group also known as “The Dukes” or “Cozy Bear” used Citrix and VPN vulnerabilities to attack various companies connected to vaccine development.
the attacker exploited a vulnerability in the Sangfor SSL VPN Server ... to replace the SangforUD.exe client binary with a trojanized version. When a client connects to the malicious server, it automatically downloaded and executed the new trojanized version of the VPN client.
The malware may perform the following functions when receiving commands from a C&C server. Execute arbitrary shell command
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
In this attack, an attacker exploited a vulnerability in the Sangfor SSL VPN Server ... to replace the SangforUD.exe client binary with a trojanized version. When a client connects to the malicious server, it automatically downloaded and executed the new trojanized version of the VPN client.
Results of command execution are send in HTTP POST request data, which is RSA-encrypted. The data in Cookie header is RC6-encrypted.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Most cyber activity by malicious actors requires infrastructure like servers on the internet. Some APT groups used several thousand Command and Control (C2) servers over the years. | Also, this article covers only HTTP(S) based infrastructure.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The malware is known to use multiple protocols to conduct C2 communications including DNS, HTTP and HTTPS.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WellMess is cited as malware used by APT29 in a certificate-based infrastructure tracking example.
A newly identified Golang-based multi-platform malware discussed in the presentation, with C2 communications and botnet operation demonstrated through reverse engineering.
Their toolkit includes ... TrailBlazer, WellMail, WellMess, WINELOADER and Living off the Land.
Custom malware attributed to SVR, historically used to target COVID-19 vaccine development organizations; authorities also state it was used against energy sector companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.