MASEPIE is a Python backdoor used by APT28, also known as Fancy Bear and Forest Blizzard, a Russian cyberespionage group attributed to GRU military unit 26165. Documented in December 2023, it enables arbitrary shell-command execution and bidirectional file transfer on compromised Windows systems, supporting payload deployment and data exfiltration. It has been used against Ukrainian government entities and Polish organizations, and in espionage campaigns targeting Western logistics and technology companies supporting aid delivery to Ukraine. MASEPIE has also been used to load STEELHOOK PowerShell scripts for browser-data theft; that collection functionality belongs to the accompanying tool rather than MASEPIE itself.
Delivery chains use spearphishing links and document-themed landing pages that abuse Windows search URI handling to expose remotely hosted WebDAV content. Victims are induced to open malicious Windows shortcuts disguised as documents, which launch a Python interpreter and execute the backdoor while displaying a decoy document. MASEPIE communicates over raw TCP channels and supports file uploads, downloads, and operator-issued shell commands. Its communications use AES-128-CBC encryption with a randomly generated 16-character key transmitted in cleartext at session initialization. APT28 has repeatedly used compromised Ubiquiti EdgeRouters as MASEPIE command-and-control infrastructure; the backdoor runs on victim endpoints rather than on those routers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In December 2023, APT28 actors wrote MASEPIE, a small Python backdoor capable of executing arbitrary commands on victim machines.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
"those protocol handlers can be leveraged to trigger the display of remote files made available through a WebDAV server"
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
The climax of APT28's elaborate scheme ends with the execution of MASEPIE, OCEANMAP, and STEELHOOK, which are designed to exfiltrate files, run arbitrary commands, and steal browser data.
"a Python interpreter and a malicious payload script (MASEPIE) would be downloaded and executed"
The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials ... CVE-2023-38831 in WinRAR for remote code execution
"following the click on a link in a phishing email and then on the landing page"
The latest campaigns observed by IBM X-Force between late November 2023 and February 2024 take advantage of the "search-ms:" URI protocol handler in Microsoft Windows to trick victims into downloading malware hosted on actor-controlled WebDAV servers.
"Ubiquiti networks devices are being used as malicious infrastructure to stage infection files, and as command and control servers or reverse-proxies."
"MASEPIE uses two raw TCP connections to a command and control (C2) server on non-standard and high TCP ports"
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool in APT28 intrusion sets, also referenced in campaigns against French entities and European government organizations.
A short-lived Python downloader used as part of APT28's fragmented single-purpose toolkit.
Malware used in the campaign for persistence and data exfiltration.
Malware used by APT28 to load PowerShell scripts in a phishing campaign targeting entities in Ukraine and Poland.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.