HATVIBE is an HTML Application (HTA)-based loader targeting Windows systems, used by the cyberespionage actor UAC-0063, also tracked as TAG-110. It establishes an initial foothold and retrieves and executes additional payloads, notably CHERRYSPY, also known as DownExPyer. HATVIBE-associated operations have targeted government entities, diplomatic missions, and research institutions in Central Asia, Europe, and Ukraine.
HATVIBE is commonly delivered through spearphishing with weaponized Microsoft Word documents and VBA macros. Campaigns have reused legitimate documents stolen from previously compromised organizations and sent malicious attachments through compromised employee email accounts. The infection chain creates an encoded HTA payload, executes it through the Windows HTML Application host, and establishes persistence with scheduled tasks; observed configurations run the loader every four minutes. HATVIBE has also been distributed through exploitation of CVE-2024-23692 in Rejetto HTTP File Server.
The loader communicates with command-and-control infrastructure using HTTP PUT requests containing a victim identifier, hostname, and username in JSON format. It interprets response markers to execute returned hexadecimal-encoded code, run VBScript, or drop files. These functions provide remote tasking and payload deployment. Its frequent pairing with CHERRYSPY supports sustained espionage access, while file theft, screenshot collection, and keylog retrieval are functions of follow-on implants rather than established native HATVIBE capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Во јули 2024 година, повеќе актери за сајбер-закани биле забележани како ја злоупотребуваат ранливоста за доставување криптовалутни мајнери и тројанци, како и малициозен софтвер познат како HATVIBE. | The article notes that, in July 2024, multiple threat actors exploited CVE-2024-23692 to deliver cryptocurrency miners, trojans, and malware known as HATVIBE.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HATVIBE acts as a loader, fetching and executing CHERRYSPY, which provides persistent, clandestine backdoor access.
...з використанням шкідливих програм HATVIBE та CHERRYSPY... буде створено ... HTA-файлу шкідливої програми HATVIBE "RecordsService"...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Слід додати, що в червні 2024 року зафіксовано численні випадки встановлення бекдору HATVIBE шляхом експлуатації вразливості (вірогідно, CVE-2024-23692) в програмному продукті HFS HTTP File Server...
Recorded Future's Insikt Group published research today detailing a Russia-aligned threat actor tracked as TAG-110 conducting espionage against government, educational, and research-related entities in Tajikistan.
На етапі первинного ураження зловмисник, маючи доступ до облікового запису електронної пошти співробітника установи, здійснив відправку копії нещодавно відправленого листа десяткам адресатів (включаючи самого відправника), замінивши оригінальний документ-вкладення іншим документом, в який було вбудовано макрос.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
Once macros are enabled, the built-in subroutine Document_Open() is automatically executed. | the generated HTA file contains an encoded VBScript (VBE) payload to interact with the C2 server, receive commands, and execute malicious actions
After opening these documents, users encounter a deceptive display: blurred pages accompanied by a standard warning banner that 'Macros have been disabled.' This social engineering technique aims to pressure the user into enabling macros | These documents were all designed to deploy the HATVIBE loader using a combination of VBA scripts.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware previously delivered through exploitation of Rejetto HTTP File Server vulnerability CVE-2024-23692. It appears as historical background; the content does not describe its capabilities or connect it to the current CVE-2026-61500 exploitation.
Malware delivered through exploitation of Rejetto HTTP File Server vulnerability CVE-2024-23692 in July 2024. It appears only as historical background; the content does not connect it to the current CVE-2026-61500 exploitation attempts or describe its capabilities.
Named malware/tool listed in APT28 reporting; exact function is not described in the provided content.
Backdoor delivered by APT28 using mshta.exe in fileless/LOLBin execution chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.