STEELHOOK is a PowerShell-based credential-stealing tool associated with APT28, the Russian GRU-linked espionage actor also tracked as Fancy Bear, Sofacy, Sednit, Forest Blizzard, and BlueDelta. It has been used in campaigns targeting government, diplomatic, logistics, defense, technology, and related organizations in Europe and Ukraine as part of broader intelligence-collection operations.
STEELHOOK is designed to collect data from Chromium-based browsers, including browser-stored information used for credential access and follow-on espionage. Reporting consistently places it alongside other APT28 tooling such as MASEPIE and OCEANMAP, with MASEPIE used to load or deploy STEELHOOK in multi-stage intrusion chains. In these operations, STEELHOOK functioned as the browser-data theft component, while companion malware provided remote execution, command handling, or additional exfiltration capability.
Observed delivery has been tied to spearphishing campaigns using lure documents and deceptive landing pages that abused Windows search protocol handling and WebDAV-hosted payload staging. These campaigns impersonated government and NGO themes and were directed at entities across Europe, the South Caucasus, Central Asia, and the Americas. STEELHOOK has also been referenced in operations against Western logistics entities and technology companies involved in support to Ukraine, reflecting APT28’s sustained focus on strategic intelligence collection tied to Russian state interests.
The malware is part of APT28’s more recent shift toward modular, disposable, single-purpose implants that complement phishing, credential harvesting, and compromised edge-device infrastructure. Within that ecosystem, STEELHOOK is best characterized as a focused browser credential and data theft utility used to support espionage objectives rather than a standalone long-term access platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2025-05-20 ⋅ US Department of Defense ⋅ Russian GRU Targeting Western Logistics Entities and Technology Companies STEELHOOK MASEPIE Headlace
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool used by Russian GRU/APT28 in campaigns targeting logistics entities and technology companies.
A PowerShell-based stealer focused on collecting data from Chromium-based browsers.
PowerShell-based information stealer used to collect Chrome browser data and exfiltrate it to command-and-control infrastructure.
Credential-stealing malware referenced as part of the toolset deployed in the campaign; no additional technical details provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.