OCEANMAP is a C#/.NET malware family associated with APT28, the Russian GRU-linked espionage group also tracked as Fancy Bear, Sofacy, Sednit, Forest Blizzard, and related aliases. It has been described as a more capable successor to CredoMap and has been used in espionage operations targeting government, diplomatic, defense, logistics, research, and other strategic organizations in Europe and Ukraine, with broader victimology extending into other Western regions.
OCEANMAP functions primarily as a backdoor and browser-data theft platform. Reported capabilities include covert command execution, file exfiltration, and theft of credentials or other sensitive data stored in web browsers. Multiple reports also describe it as using email-based command and control, specifically leveraging IMAP and IMAP drafts as a communications channel, which supports stealth and blends malicious traffic with legitimate mail activity. In some observed intrusion chains, OCEANMAP was deployed alongside MASEPIE and STEELHOOK, with the combined toolset enabling arbitrary command execution, browser data theft, and collection of victim files.
Observed delivery has been tied to spearphishing campaigns using lure documents themed around government, NGOs, finance, critical infrastructure, maritime security, healthcare, business, and defense topics. In late 2023 and early 2024 campaigns, victims were tricked through Windows search protocol abuse and WebDAV-hosted payload staging, after which MASEPIE acted as an earlier-stage component and loaded OCEANMAP to establish persistence and provide discreet post-compromise access. Reporting also indicates OCEANMAP updates were deployed through SteelHook and MasePie in credential-theft operations.
The malware is part of APT28’s broader shift toward modular, disposable espionage tooling and its use of compromised edge devices and low-cost infrastructure to support operations. High-confidence reporting places OCEANMAP in campaigns against Ukrainian and French entities and in wider APT28 phishing activity across Europe, the South Caucasus, Central Asia, and the Americas. Its role in those operations is consistent with strategic intelligence collection rather than disruptive or destructive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...using phishing emails to distribute malware families like HeadLace and OCEANMAP...
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-04-29 ⋅ CERT-FR ⋅ Targeting and Compromise of French Entities Using the APT28 Intrusion Set STEELHOOK MASEPIE Mocky LNK OCEANMAP
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
The climax of APT28's elaborate scheme ends with the execution of MASEPIE, OCEANMAP, and STEELHOOK, which are designed to exfiltrate files, run arbitrary commands, and steal browser data.
The latest campaigns observed by IBM X-Force between late November 2023 and February 2024 take advantage of the "search-ms:" URI protocol handler in Microsoft Windows to trick victims into downloading malware hosted on actor-controlled WebDAV servers.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28 backdoor/tool used in European espionage campaigns and post-compromise activity.
A C# backdoor using IMAP drafts for command-and-control, described as a more capable successor to CredoMap.
Backdoor used for persistence and discreet command execution on infected systems.
Malware family distributed via phishing in APT28-linked activity (details not provided in the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.