CHERRYSPY, also known as DownExPyer, is a Python-based Windows backdoor used by the Russia-aligned cyberespionage actor UAC-0063, also tracked as TAG-110. It provides persistent, covert remote access to compromised systems and supports espionage operations targeting government and research organizations. Documented deployments include attacks against Ukrainian state bodies and a Ukrainian scientific research institution.
CHERRYSPY is deployed after initial compromise, including through infection chains in which malicious Microsoft Word macros install HATVIBE, which subsequently fetches and executes the backdoor. Spearphishing campaigns have used government-themed document lures and compromised employee email accounts to distribute malicious attachments. Earlier CHERRYSPY versions used pyArmor obfuscation; a variant observed in July 2024 was compiled as a Python extension DLL and deployed alongside a Python interpreter.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HATVIBE acts as a loader, fetching and executing CHERRYSPY, which provides persistent, clandestine backdoor access.
...на комп'ютер в каталог "C:\ProgramData\Python" згодом завантажено Python-інтерпретатор та файл шкідливої програми CHERRYSPY, який, на відміну від попередньої версії, обфускованої за допомогою pyArmor, скомпільовано в .pyd (DLL) файл.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Recorded Future's Insikt Group published research today detailing a Russia-aligned threat actor tracked as TAG-110 conducting espionage against government, educational, and research-related entities in Tajikistan.
На етапі первинного ураження зловмисник, маючи доступ до облікового запису електронної пошти співробітника установи, здійснив відправку копії нещодавно відправленого листа десяткам адресатів (включаючи самого відправника), замінивши оригінальний документ-вкладення іншим документом, в який було вбудовано макрос.
The A5 task results in a command execution... For example: A5(... command=['', '', '', 'taskkill /f /im pythonw.exe'])
Present with the files is a VBA macro that's responsible for placing the document template in the Microsoft Word startup folder for automatic execution and subsequently initiating communications with a command-and-control (C2) server and potentially executing additional VBA code supplied with C2 responses.
The A3 task is designed for file exfiltration... only files matching the specified criteria are collected.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor fetched and executed by HATVIBE to provide persistent, clandestine access. The reference places it in an espionage campaign targeting government officials through spearphishing and malicious Word documents.
A malware strain in the TAG-110/UAC-0063 espionage toolkit, used in attacks against Ukrainian state bodies and cited as a likely follow-on payload in later campaigns.
A malware family delivered later in TAG-110's phishing infection chain after macro-enabled Word documents establish persistence and command-and-control.
Custom malware family used by TAG-110 in espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.