JHUHUGIT, also known as Seduploader, is a Windows reconnaissance backdoor used by APT28, the Russian cyberespionage group also known as Fancy Bear, Sofacy, and Group 74. It supports process enumeration, network-adapter information collection, screenshot capture, data and configuration exfiltration, remote code execution, and file downloading. Its architecture includes a dropper and a payload.
JHUHUGIT has been delivered through weaponized Microsoft Word documents using malicious VBA macros or Dynamic Data Exchange to execute PowerShell commands. Document lures have included a cybersecurity conference flyer. The malware can execute through the Windows Rundll32 utility and inject its functions into browser processes. Its command-and-control connectivity follows a fallback sequence: attempting a direct connection, using the host's proxy settings if that fails, and finally injecting code into a running browser. Some variants Base64-encode HTTP POST data.
Persistence mechanisms include scheduled tasks triggered at user logon, registry-based autostart entries, logon scripts, and COM hijacking. Some variants have exploited CVE-2015-1701 and CVE-2015-2387 for privilege escalation, although this functionality is not present in every dropper. Screenshot implementations include simulating the screenshot key and converting the clipboard image to JPEG, as well as capture through Windows graphics APIs. The dropper can delete itself, and other variants can delete specified files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT28 has exploited CVE-2015-1701 to escalate privileges. JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.
APT28 has exploited CVE-2015-2387 to escalate privileges. JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges. | JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.
2017-10-19 ⋅ Proofpoint ⋅ APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed | 2017-10-19 ⋅ Proofpoint ⋅ APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed Seduploader
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
IoCs Table 2 lists a phishing document (f3805382ae2e23ff1147301d131a06e00e4ff75f) detected as Win32/Exploit.CVE-2016-4117.A; the report describes Sednit’s DealersChoice platform embedding Adobe Flash Player exploits in malicious Office documents.
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
The RTF attachment exploits the CVE-2015-1641 vulnerability to drop two DLLs on the system... This particular case is one among a series of attacks using the CVE-2015-1641 vulnerability launched from April 2016 by the Sednit group. | Seduploader serves as reconnaissance malware. It is made up of two distinct components: a dropper and the persistent payload installed by this dropper.
Seduploader serves as reconnaissance malware. It is made up of two distinct components: a dropper and the persistent payload installed by this dropper. | CVE-2015-2424 Microsoft Office 0-day at the time the Sednit group used it. Seduploader deployed with targeted phishing emails using a 0-day exploit for the Microsoft Office vulnerability CVE-2015-2424.
The JHUHUGIT implant became a relatively popular first stage for the Sofacy attacks and was used again with a Java zero-day (CVE-2015-2590) in July 2015. | JHUHUGIT (which is built with code from the Carberp sources)... its JHUHUGIT implant was delivered through a Flash zero-day and used a Windows EoP exploit to break out of the sandbox.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1510 / CVE-2014-1511 Firefox.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1510 / CVE-2014-1511 Firefox.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2012-0158 Microsoft Office.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2014-1761 Microsoft Word 0-day at the time the Sednit group used it.
The vulnerability CVE-2014-6332 was discovered in May 2014... Soon after the disclosure, a proof-of-concept was released... in October 2015 a simple revamped version of the original proof-of-concept was added to Sedkit. But the Sednit group went one step further in February 2016 by deploying a different exploit for this vulnerability.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2010-3333 Microsoft Office.
Table 3. Sedkit exploited vulnerabilities: CVE-2015-5119 Adobe Flash. Revamped from Hacking Team leaked data.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2013-2729 Adobe Acrobat Reader.
Table 3. Sedkit exploited vulnerabilities: CVE-2013-3897 Internet Explorer 8.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2009-3129 Microsoft Excel.
CVE-2015-3043 Adobe Flash 0-day at the time Sedkit used it.
CVE-2015-7645 Adobe Flash 0-day at the time Sedkit used it.
Table 3. Sedkit exploited vulnerabilities: CVE-2013-1347 Internet Explorer 8.
CVE-2015-4902 Java 0-day at the time Sedkit used it.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1776 Internet Explorer 11.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Komplex, SlimAgent, JHUHUGIT, Seduploader, Zebrocy | SlimAgent, JHUHUGIT, Seduploader, Zebrocy, PythocyDbg
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
174 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
73 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader used extensively by APT28/Sofacy in spearphishing and exploit-driven espionage campaigns.
A first-stage loader delivered via spear phishing or SedKit as part of APT28's earlier implant chain.
SlimAgent, JHUHUGIT, Seduploader, Zebrocy, PythocyDbg
Malware that injects its own functions into browser processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.