WellMess is a cross-platform remote access trojan observed in intrusions since at least January 2018. It has Go-based variants compiled for Windows and Linux, including 32-bit and 64-bit builds, and a Windows variant implemented in .NET. Its core capabilities include arbitrary shell command execution, file upload and download, and exfiltration of files and system information. Windows variants can also execute PowerShell scripts received from command-and-control servers. WellMess collects host details such as the current username, user domain, and IP address and transmits information to its operators.
WellMess uses HTTP, HTTPS, and DNS for command-and-control communications. It supports decoding and decrypting incoming commands and uses Base64 encoding and cryptographic mechanisms involving RC6, AES, and RSA to protect communication data. Some variants encrypt dynamically generated AES keys with an embedded RSA public key.
WellMess infections have been identified in Japanese organizations. In 2020, the United Kingdom, Canada, and United States governments attributed WellMess intrusions targeting COVID-19 vaccine development organizations to APT29, a cyberespionage group associated with Russia's Foreign Intelligence Service. WellMess and WellMail were used in operations aimed at stealing vaccine-related intellectual property in the United States, United Kingdom, and Canada. In these operations, WellMess was typically deployed after initial compromise through an unpatched, publicly known vulnerability, with subsequent activity targeting vaccine research repositories and Active Directory servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
How WellMess malware has been used to target COVID-19 vaccines.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
The WellMess malware is an excellent example of how examination of infrastructure and the techniques used in an attack can lead to different conclusions.
“…deployment of custom malware known as WellMess, WellMail, and Sorefang to target organizations involved in COVID-19 vaccine development.”
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Most cyber activity by malicious actors requires infrastructure like servers on the internet. Some APT groups used several thousand Command and Control (C2) servers over the years. | Also, this article covers only HTTP(S) based infrastructure.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
63 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
52 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WellMess is cited as malware used by APT29 in a certificate-based infrastructure tracking example.
Custom malware used by APT29 in its 2020 campaign targeting COVID-19 vaccine development organizations in the United States, United Kingdom, and Canada to steal vaccine-related intellectual property.
A newly identified Golang-based multi-platform malware discussed in the presentation, with C2 communications and botnet operation demonstrated through reverse engineering.
Their toolkit includes ... TrailBlazer, WellMail, WellMess, WINELOADER and Living off the Land.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.