OLDBAIT is Windows credential-stealing malware used by APT28, also known as Fancy Bear, a cyberespionage group attributed to Russia’s GRU military intelligence service. It harvests stored credentials from web browsers and email clients, including Internet Explorer, Mozilla Firefox, and Eudora. Its credential collection functionality supports the theft of application passwords from compromised systems. OLDBAIT employs obfuscation and masquerades as a Microsoft Media Player-related update, using deceptively named installation artifacts to appear legitimate. It is part of APT28’s broader espionage toolset, although specific OLDBAIT delivery mechanisms and industry targeting are not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The APT28 software table lists OLDBAIT with credentials from password stores and web browsers, web and mail protocols, and obfuscation.
Attributed to the criminal group Smoky Spider, a group that uses SmokeLoader and Sasfis, loader and downloader respectively.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Malware belonging to the SASFIS family are known to be downloaded on systems while visiting sites that have been compromised using a particular exploit pack known as "Eleonore".
Asprox initially used the name of a trusted delivery company as the bait to trick users into opening an executable email attachment with a document icon. In early August, however, it was observed that the spam had been improved by replacing the email content with an image containing the same text.
when a malicious executable such as FakeAV is downloaded through use of the c=rdl command, a registry entry will be created related to this downloaded file stored in the file system.
The injection technique provides a way to release the malicious code to a section and attach it to a suspended legitimate window process. The malicious code will be executed when the process is resumed in the end.
The new Sasfis is packed with a custom packer... the initial part of the custom packer consists of obfuscating instructions, sometimes combined with anti-debug or anti-virtual-environment techniques.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
The injection technique provides a way to release the malicious code to a section and attach it to a suspended legitimate window process. The malicious code will be executed when the process is resumed in the end.
Winlogon Shell = "Explorer.exe rundll32.exe {4 random letters}.{3 random letters} {6 random letters]}"
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
ips is the local IP of the botnet client (for collecting data on local network topology).
The payload of Sasfis acts as a listening client in the botnet operation... The traffic that would be accepted by the C&C server is described below: [C&C server URL]/forum/index.php?r=gate&id=XXXXXXX&group=XXXXX&debug=0
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Winexe, OCEANMAP, OLDBAIT, ProcDump, WinIDS
Sasfis is mentioned as a downloader used by the Smoky Spider criminal group alongside SmokeLoader.
Collects credentials from multiple email clients.
Malware that collects credentials from browsers and email clients.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.