EnvyScout is an HTML and JavaScript-based dropper used by APT29, also known as Nobelium and Cozy Bear, since at least 2021. It supports spearphishing operations against Windows systems, particularly in government agencies, foreign ministries, embassies, and other diplomatic organizations. APT29 is attributed to Russia’s Foreign Intelligence Service (SVR).
EnvyScout is delivered through malicious email attachments or links in phishing messages and lure documents, including PDFs, that direct recipients to compromised websites. Its lures have included diplomatic meeting agendas and COVID-19-related information. It uses HTML smuggling to decode embedded malicious data in the victim’s browser and write payloads, including ISO disk images, to disk through JavaScript. Implementations have used a modified version of the open-source FileSaver tool. The resulting infection chains typically require victims to open the downloaded disk image and execute a shortcut or another disguised file, leading to malicious DLL execution, sometimes through DLL sideloading with signed legitimate executables.
EnvyScout can conceal malicious executables using hidden files and directories and use folder icons to encourage execution. It also supports collection of sensitive NTLM authentication material through forced authentication. It has delivered SNOWYAMBER, QUARTERRIG, and HALFRIG, and has featured in infection chains deploying Cobalt Strike. Its principal role is payload delivery rather than providing the capabilities of those subsequent implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"If the device targeted was an Apple iOS device, the user was redirected to another server under NOBELIUM control, where the since-patched zero-day exploit for CVE-2021-1879 was served."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EnvyScout ... Forced Authentication ... Obfuscated Files or Information: HTML Smuggling ... Phishing: Spearphishing Attachment.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
This file contains malicious JavaScript designed to create an .ISO file on the user’s computer.
The original HTML Smuggling attack conducted by Nobelium used EnvyScout to convert a text blob into an .ISO file.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A delivery script used by APT29 since 2021 to facilitate downloads of SNOWYAMBER, QUARTERRIG, or HALFRIG in phishing-based intrusion chains.
Previously reported malware/tool associated with NOBELIUM/APT29 in espionage campaigns.
A dropper used by APT29 since at least 2021.
HTML-based dropper used in initial access activity by APT29/Nobelium.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.