Downdelph, also known as Delphacy, is a lightweight Delphi-based downloader associated with the Sednit intrusion set, also tracked as APT28, Fancy Bear, and Sofacy. It has been used as part of the group’s Windows espionage toolchain and has been observed alongside additional stealth components including a bootkit and rootkit to maintain long-term access on compromised systems.
Downdelph is designed to retrieve and execute follow-on payloads after initial compromise. Its command-and-control traffic uses RC4-encrypted responses, and its request encoding inserts pseudo-random characters between legitimate characters to complicate signature creation and protocol analysis. The malware has also been linked to process injection tradecraft through a companion component that injects a Downdelph DLL into explorer.exe.
A notable aspect of Downdelph is its use of privilege-escalation mechanisms on Windows. It has been reported to bypass User Account Control through a custom RedirectEXE shim database and to abuse DLL search order hijacking involving sysprep.exe to obtain elevated execution. These behaviors indicate a role beyond simple payload retrieval, enabling post-compromise execution with higher privileges and improved resilience against user-facing security controls.
Downdelph is part of the broader Sednit malware ecosystem used in targeted espionage operations against government, diplomatic, defense, political, and other geopolitically relevant organizations, particularly in Europe and Eastern Europe. Its lightweight design, downloader role, obfuscated network protocol, and integration with persistence and privilege-escalation tooling make it a practical staging component for more capable second-stage implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2016-09-11 ⋅ ESET Research ⋅ En Route with Sednit - Part 3: A Mysterious Downloader Downdelph
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples include “PowerPoint mouse-over event abused to deliver Graphite implants”, “BREXIT-themed lure document that delivers ZEKAPAB malware”, “fake NATO training docs to breach govt networks”, and repeated references to lure documents delivering Zebrocy or Seduploader.
One listed item explicitly names “T1055 Process Injection” and includes APT28-linked malware such as Downdelph among examples.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
One listed item explicitly names “T1055 Process Injection” and includes APT28-linked malware such as Downdelph among examples.
APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader used in Sednit/APT28 operations.
Backdoor that encrypts C2 responses with RC4.
Payload DLL associated with HIDEDRV and injected into explorer.exe.
Malware that uses a custom RedirectEXE shim database to bypass UAC and elevate privileges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.