Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 2 actorsExploits 2 CVEs

Headlace

HeadLace is a multi-component backdoor malware family associated with the Russian GRU-linked threat actor APT28 (also tracked as Fancy Bear, Forest Blizzard, BlueDelta, and Unit 26165). Public reporting describes it as a CMD/VBS/BAT-based backdoor used in espionage campaigns from at least 2023 onward. It has been delivered primarily through spearphishing and phishing campaigns, including malicious ZIP archives, lure documents, and phishing emails crafted in victims’ native languages. Reported delivery chains have abused free and legitimate web services such as Mocky.IO/run.mocky.io, webhook.site, InfinityFree, and other cloud or web platforms to redirect victims, host payloads, and distribute commands.

HeadLace has been used for persistence, reconnaissance, credential collection, and data exfiltration. Reported commanding mechanisms include web endpoints on Mocky.IO. ANSSI reported that commands delivered through Mocky.IO were used to gather login credentials, collect information about the victim information system, and deploy offensive tools; persistence could include creation of a scheduled task. CERT Polska described an infection chain matching previously documented HeadLace behavior in which a ZIP archive contained a decoy executable, a BAT script, and a malicious WindowsCodecs.dll used for DLL side-loading. Subsequent stages abused Microsoft Edge, including headless mode, to fetch and execute additional scripts from webhook.site in a recurring loop, while displaying decoy images to reduce suspicion. The final observed stage collected the public IP address via ipinfo.io and directory listings from user and program folders, then sent the data to a command-and-control endpoint.

Victimology in the provided reporting includes critical energy infrastructure in Ukraine, Polish government institutions, French entities, European governmental and diplomatic targets, research and policy-focused organizations, logistics entities, technology companies, and organizations involved in humanitarian aid allocation or aid delivery to Ukraine. IBM X-Force reported a December 2023 campaign using Israel-Hamas-war-themed lure documents derived from authentic academic, finance, diplomatic, government, educational, and NGO materials to deliver the HeadLace backdoor, with country-based filtering restricting malware delivery to intended victims. Joint government advisories also state that HEADLACE was used in the ongoing GRU campaign against Western logistics entities and technology companies supporting Ukraine, where it was used alongside MASEPIE for persistence and data exfiltration.

High-confidence infrastructure and behavioral indicators mentioned in the content include use of Mocky.IO/run.mocky.io and webhook.site in delivery and command distribution, malicious ZIP archives, DLL side-loading via a fake WindowsCodecs.dll, BAT/VBS/CMD script chains, scheduled-task persistence, Microsoft Edge headless execution, and host reconnaissance including public IP discovery through ipinfo.io.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2023-23397Microsoft Outlook for Windows Net-NTLMv2 Hash Leak via Reminder UNC Path

The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.

via thecyberexpress com vulnerabilitiesthecyberexpress.com
CVE-2023-38831Arbitrary Code Execution in WinRAR Archive File Handling

The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.

via thecyberexpress com vulnerabilitiesthecyberexpress.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
APT28

For example, on September 4, 2023, CERT-UA reported a phishing campaign in which BlueDelta leveraged Headlace information-stealing malware to target critical energy infrastructure in Ukraine.

via recorded future blogrecordedfuture.com
GRU Unit 26165

The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.

via thecyberexpress com vulnerabilitiesthecyberexpress.com
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1587.001MalwareEvidence1

For example, in January 2022, GRU Unit 29155 launched WhisperGate, a wiper malware attack that overwrote the master boot records of Ukrainian government systems.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution

T1566PhishingEvidence3

In December 2023, Ukraine’s Computer Emergency Response Team (CERT-UA) reported that Russian state cyber unit APT28 was targeting entities in Ukraine and Poland with phishing campaigns... On September 4, 2023, CERT-UA reported a phishing campaign in which BlueDelta leveraged Headlace information-stealing malware to target critical energy infrastructure in Ukraine.

Execution

4 techniques
T1053Scheduled Task/JobEvidence1

“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”

T1059.003Windows Command ShellEvidence1

HeadLace : multi-component backdoor (CMD/VBS/BAT).

T1059.005Visual BasicEvidence1

HeadLace : multi-component backdoor (CMD/VBS/BAT).

T1203Exploitation for Client ExecutionEvidence1

The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials ... CVE-2023-38831 in WinRAR for remote code execution

Persistence

1 technique
T1053Scheduled Task/JobEvidence1

“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”

Privilege Escalation

1 technique
T1053Scheduled Task/JobEvidence1

“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”

Stealth

1 technique
T1218System Binary Proxy ExecutionEvidence1

Throughout three phases, BlueDelta used phishing emails, legitimate internet services, and living-off-the-land binaries to extract intelligence from key networks across Europe.

Command and Control

2 techniques
T1102Web ServiceEvidence1

“This backdoor relied on the distribution of commands from web endpoints of the Mocky.IO service.”

T1105Ingress Tool TransferEvidence1

“…links redirecting users… to deliver malicious ZIP archives containing the HeadLace backdoor.”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.