HeadLace is a modular, multistage Windows backdoor used by the Russian GRU-linked cyberespionage group APT28, also tracked as Fancy Bear, BlueDelta, Fighting Ursa, and Forest Blizzard. It combines batch, command-shell, and VBScript components to execute attacker-supplied commands and follow-on payloads during early intrusion stages. Its communications use browser automation, including hidden or headless Microsoft Edge execution, and abuse legitimate internet services for command-and-control and payload staging. HeadLace has been used in campaigns targeting European organizations, diplomats, Ukrainian energy infrastructure, and Western logistics and technology organizations supporting Ukraine. Its operational roles include persistence and data exfiltration.
Delivery campaigns have used phishing and topical social-engineering lures, including Israel–Hamas war decoys and a fraudulent diplomatic vehicle-sale advertisement. In a documented 2024 infection chain, a malicious web page checked whether visitors were running Windows and delivered an archive containing a legitimate executable disguised as an image, a malicious DLL, and a batch script. The executable sideloaded the HeadLace DLL, which launched the script. Microsoft Edge then retrieved a subsequent command-script payload from a legitimate public web service for local execution. Encoded browser content, discreet script execution, abuse of trusted software and services, and deletion of execution artifacts help reduce the malware's visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”
HOOKEDGE is a lightweight Windows batch backdoor that enables remote command execution by retrieving arbitrary .cmd payloads from a staging webhook.
Changes included modifications to lure documents and VBA obfuscation... Second-stage payloads retrieved by HOOKEDGE also share... base64 encoding schemes with payloads previously observed in HEADLACE campaigns.
The second-stage payloads retrieved by HOOKEDGE share JavaScript code ... using identical variable names, properties, structure, and base64 encoding schemes for automated file downloads.
Table 1 above shows that the first file IMG-387470302099.jpg.exe has a double file extension of .jpg.exe. Windows hosts with a default configuration hide file extensions, so the .jpg.exe file extension only shows as .jpg in the file name.
Finally, the batch file executes IMG387470302099.cmd, then deletes itself as a way to remove any obvious trace of malicious activity.
Throughout three phases, BlueDelta used phishing emails, legitimate internet services, and living-off-the-land binaries to extract intelligence from key networks across Europe.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
Outbound connections from infected hosts are directed to a legitimate HTTPS service, with a web browser serving as the HTTP client.
HOOKEDGE routes command retrieval and data exfiltration through webhook[.]site using Microsoft Edge.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family/tool identified only as closely related to HOOKEDGE in this reference; no further functionality is described.
An earlier backdoor described as the predecessor from which HOOKEDGE evolved. No additional operational capabilities are provided.
An earlier backdoor from which HOOKEDGE is described as evolving. The content provides no further functional detail.
A previously documented BlueDelta Windows backdoor and apparent evolutionary predecessor to HOOKEDGE. The content states that it uses Windows batch scripting, legitimate internet services for C2 and exfiltration, and hidden browser instances for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.