MASEPIE is a bespoke Python malware family associated with APT28, the Russian GRU-linked espionage group also tracked as Fancy Bear and Sednit. It has been used in campaigns targeting government, logistics, technology, defense-related, and other strategic organizations in Ukraine, Poland, France, and broader Europe, including operations aligned with intelligence collection on support to Ukraine.
MASEPIE is best characterized as a downloader and lightweight backdoor used to establish remote access and support follow-on collection. Reported functionality includes arbitrary command execution, file upload and download, and use as a staging component for additional tooling. In some APT28 operations, MASEPIE has been used to load or deploy STEELHOOK, a PowerShell-based browser data theft tool, and has been linked with broader intrusion chains involving OCEANMAP. Public reporting also associates MASEPIE with persistence and data exfiltration in GRU campaigns.
Observed delivery has centered on spearphishing. Campaigns used lure documents and malicious links that abused Windows URI handling and WebDAV-based staging to induce victims to retrieve and execute payloads, including via shortcut-based execution chains. Reporting also describes phishing messages sent from compromised accounts and themed around government, NGO, logistics, and geopolitical subjects. In later GRU logistics-targeting activity, MASEPIE was also delivered through spearphishing alongside other established intrusion methods.
MASEPIE runs on Windows systems by leveraging Python execution on the victim host. Its role in APT28 tradecraft reflects the group’s shift toward disposable, single-purpose implants and low-cost infrastructure, including compromised edge devices used for staging or command-and-control support. The malware has primarily been used in espionage operations focused on remote access, collection, and enabling subsequent theft of sensitive operational or browser-derived data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-05-20 ⋅ US Department of Defense ⋅ Russian GRU Targeting Western Logistics Entities and Technology Companies STEELHOOK MASEPIE Headlace
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
"those protocol handlers can be leveraged to trigger the display of remote files made available through a WebDAV server"
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
The climax of APT28's elaborate scheme ends with the execution of MASEPIE, OCEANMAP, and STEELHOOK, which are designed to exfiltrate files, run arbitrary commands, and steal browser data.
"a Python interpreter and a malicious payload script (MASEPIE) would be downloaded and executed"
The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials ... CVE-2023-38831 in WinRAR for remote code execution
"following the click on a link in a phishing email and then on the landing page"
The latest campaigns observed by IBM X-Force between late November 2023 and February 2024 take advantage of the "search-ms:" URI protocol handler in Microsoft Windows to trick victims into downloading malware hosted on actor-controlled WebDAV servers.
"Ubiquiti networks devices are being used as malicious infrastructure to stage infection files, and as command and control servers or reverse-proxies."
"MASEPIE uses two raw TCP connections to a command and control (C2) server on non-standard and high TCP ports"
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool in APT28 intrusion sets, also referenced in campaigns against French entities and European government organizations.
A short-lived Python downloader used as part of APT28's fragmented single-purpose toolkit.
Malware used in the campaign for persistence and data exfiltration.
Malware used by APT28 to load PowerShell scripts in a phishing campaign targeting entities in Ukraine and Poland.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.