HeadLace is a bespoke multi-component Windows backdoor associated with the Russian GRU-linked espionage actor APT28, also tracked as Fancy Bear, Sofacy, Fighting Ursa, Forest Blizzard, BlueDelta, and ITG05. It has been used in targeted cyber-espionage operations against government, diplomatic, logistics, defense, critical infrastructure, and related organizations, including campaigns focused on Ukraine and European entities. Reported targeting themes include humanitarian aid, foreign policy, logistics supporting Ukraine, and diplomatic or policy-oriented audiences.
HeadLace is designed for staged execution and persistent remote access. Public reporting describes it as a modular backdoor implemented through command, batch, and VBScript components, with use for persistence and data exfiltration. In some campaigns it also supported collection of login credentials and host information, and facilitated deployment or retrieval of follow-on commands from web-based endpoints. Observed tradecraft includes DLL sideloading through a legitimate Windows binary, execution chains driven by batch scripts, abuse of Microsoft Edge to fetch and run additional stages, recurring task loops for continued command retrieval, and cleanup actions intended to reduce visible traces. Some reporting also notes scheduled-task creation as a persistence mechanism.
Delivery has primarily relied on spearphishing and phishing lures tailored to specific victim sets. Documented lures included war-themed decoys, fake diplomatic content, and social-engineering themes such as a vehicle sale advertisement or photo archive. Campaigns used public and low-cost web services for staging, redirection, and command distribution, reflecting APT28's broader preference for blending malicious activity with legitimate infrastructure. HeadLace has also been delivered in malicious archives and through infection chains abusing free web platforms and web endpoints for command retrieval.
HeadLace forms part of APT28's newer generation of disposable and modular espionage tooling alongside malware such as MASEPIE, OCEANMAP, STEELHOOK, and CredoMap. Its operational role is consistent with intelligence collection, foothold establishment, persistence, and exfiltration in support of Russian state espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-05-20 ⋅ US Department of Defense ⋅ Russian GRU Targeting Western Logistics Entities and Technology Companies STEELHOOK MASEPIE Headlace
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”
This function is solely meant to execute the last file within the ZIP archive, zqtxmo.bat... Finally, the batch file executes IMG387470302099.cmd, then deletes itself as a way to remove any obvious trace of malicious activity.
Table 1 above shows that the first file IMG-387470302099.jpg.exe has a double file extension of .jpg.exe. Windows hosts with a default configuration hide file extensions, so the .jpg.exe file extension only shows as .jpg in the file name.
Finally, the batch file executes IMG387470302099.cmd, then deletes itself as a way to remove any obvious trace of malicious activity.
Throughout three phases, BlueDelta used phishing emails, legitimate internet services, and living-off-the-land binaries to extract intelligence from key networks across Europe.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool associated with Russian GRU/APT28 targeting logistics and technology sectors.
A multi-component backdoor implemented through CMD, VBS, and BAT components as part of APT28's short-lived modular arsenal.
Malware used in the campaign for persistence and data exfiltration.
HeadLace is a malware used by APT28 for credential harvesting, particularly targeting users of webmail services like UKR[.]net. It is deployed as part of phishing campaigns to steal login credentials and two-factor authentication codes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.