SunSeed is a Lua-based downloader associated with the intrusion cluster UAC-0064 and with activity tracked as Asylum Ambuscade. It has been used in espionage-oriented phishing campaigns targeting European government personnel involved in refugee logistics after the start of Russia’s full-scale invasion of Ukraine, and it has also appeared as part of broader Asylum Ambuscade operations against government entities in Europe and Central Asia. The malware is typically delivered through spearphishing documents containing malicious macros that invoke Windows Installer to silently retrieve and install an MSI package. In later related activity, comparable first-stage delivery chains also used exploitation of Follina (CVE-2022-30190). SunSeed has additionally been described as functionally similar to the WasabiSeed VBS tool used in the Screentime cluster.
Once installed, SunSeed runs via a Lua interpreter on Windows and acts as a first-stage downloader. It collects the victim system’s C: drive serial number and uses it as part of periodic HTTP beaconing to command-and-control infrastructure. Its purpose is to fetch and execute additional Lua code and stage follow-on payloads. Reported follow-on actions include downloading an install script that deploys AHKBOT together with a legitimate AutoHotkey interpreter, as well as a move script used to reassign victim management between command-and-control servers. In observed Asylum Ambuscade chains, SunSeed serves as the bridge between initial access and more capable second-stage tooling.
SunSeed-supported operations have been linked to intelligence collection objectives, including theft of confidential information and webmail credentials from official government portals. Through downstream tooling deployed after SunSeed, operators have conducted surveillance and post-compromise activity including keylogging, screenshot capture, browser credential theft, domain discovery, process and window enumeration, hidden remote desktop capability, and delivery of additional payloads such as Cobalt Strike and Remote Utilities RAT. The malware therefore functions primarily as an initial downloader within a modular intrusion ecosystem rather than as a standalone end-stage implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The email included a malicious macro attachment which attempted to download a Lua-based malware dubbed SunSeed.
The email included a malicious macro attachment which attempted to download a Lua-based malware dubbed SunSeed.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lua-based looping downloader (not directly observed in the TA866 campaigns in this report) described as functionally similar to WasabiSeed: repeatedly downloads payloads in a loop and uses the C: drive serial as part of the URL path.
A named malware family associated with attacks on Ukrainian infrastructure.
Lua-based downloader delivered via macro-enabled Excel attachment that uses Windows Installer (msiexec/InstallProduct) to fetch an MSI, installs Lua runtime/dependencies, establishes persistence via a Startup LNK, and repeatedly beacons over HTTP (LuaSocket UA) to retrieve and execute additional Lua code; appends the host C: volume serial number to C2 requests for victim tracking/selection.
Script-based first-stage downloader (Lua/Tcl/VBS variants) that contacts a C2 over HTTP, retrieves and executes additional code (Lua variants), and can download/install the next stage (e.g., AHKBOT via AutoHotkey interpreter).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.