CSPY Downloader is a Windows malware downloader associated with malicious document campaigns that rely on embedded macros for execution. It has been observed using Windows Task Scheduler tradecraft, including the schtasks utility and abuse of the SilentCleanup scheduled task, to execute with elevated privileges and bypass User Account Control. The malware also modifies the Windows Registry to support execution and can later remove the values it created, indicating cleanup and defense-evasion behavior. Additional anti-forensic behavior includes self-deletion after use. Samples have been observed packed with UPX and signed with revoked certificates, both consistent with efforts to hinder analysis and reduce detection. The available reporting supports its role as a downloader focused on establishing execution on Windows hosts and retrieving or launching follow-on payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CSPY Downloader has been delivered via malicious documents with embedded macros.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
The content repeatedly mentions malicious macros in Word/Excel documents, such as "enable macros," "embedded macros," and "macro-enabled documents."
has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... has required user execution of a malicious MSI installer... has been executed through user installation of an executable disguised as a flash installer.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
BADHATCH can utilize the CMSTPLUA COM interface and the SilentCleanup task to bypass UAC. CHIMNEYSWEEP can make use of the Windows SilentCleanup scheduled task to execute its payload with elevated privileges. CSPY Downloader can bypass UAC using the SilentCleanup task to execute the binary with elevated privileges.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader delivered through malicious documents containing embedded macros.
Downloader malware with self-deletion capability.
Downloader that abuses schtasks for UAC bypass.
Downloader that writes to the Registry to support task execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.