Mail-O is a Windows malware family used in espionage intrusions against Russian government organizations, including entities associated with the FSB. It has been described both as a stealthy backdoor and, more specifically from technical analysis, as a downloader that masquerades as legitimate Mail.ru Disk-O software. The malware imitates the appearance and network behavior of that software, checks for signs of a legitimate Disk-O installation, and uses a real Mail.ru cloud service as part of its command-and-control workflow to blend malicious traffic with normal-looking cloud communications.
Mail-O exposes service-oriented functionality and is designed to run as a Windows service. Its ServiceMain routine initializes service handling and invokes its main execution logic. The malware gathers basic victim information, encrypts it, sends it to remote infrastructure via Mail.ru cloud services, retrieves a next-stage payload, writes that payload locally, and executes it. Analysis also notes logic to launch a PsExec-related component if present, indicating integration with broader post-compromise tradecraft.
Operational reporting ties Mail-O to campaigns in which attackers stole confidential information from mail servers, document management systems, file servers, and workstations after gaining broad access to victim environments. Initial access in those operations reportedly included spearphishing, exploitation of web application vulnerabilities, and compromise of government contractors. Mail-O was paired with Webdav-O in some intrusions, with both implants used for command execution and data theft while attempting to evade antivirus detection.
Technical and behavioral overlaps have linked Mail-O to PhantomNet, also known as SManager, and to related tooling such as TManger. Reported similarities include shared service-style structure and the unusual exported function name "Entery." These overlaps have been used to associate the malware with the TA428 activity cluster, also tracked by some researchers as ThunderCats, a suspected Chinese-linked espionage actor with a history of targeting Russian and Southeast Asian entities. Mail-O is therefore best understood as a cloud-masquerading Windows downloader/backdoor used in targeted state-aligned cyberespionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several researchers had previously described a series of attacks using WebDav-O and Mail-O.
This research focuses on the ‘Mail-O’ malware used against the FSB and other Russian government organizations... In line with the findings of the NKTsKI-Rostelecom report, the Mail-O malware acts as a downloader with a thin veneer of similarity to the legitimate Mail.ru Disk-O software.
This research focuses on the ‘Mail-O’ malware used against the FSB and other Russian government organizations... In line with the findings of the NKTsKI-Rostelecom report, the Mail-O malware acts as a downloader with a thin veneer of similarity to the legitimate Mail.ru Disk-O software.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
To breach Russian federal agencies, Rostelecom and NKTsKI said the attackers used a broad set of entry vectors that included spear-phishing, exploiting vulnerabilities in web applications...
...the attackers would deploy two never-before-seen malware strains named Mail-O and Webdav-O, both stealthy backdoors that the intruders used to execute commands on infected hosts and steal data.
ServiceMain takes a service name as an argument and attempts to register a service control handler with a specific HandlerProc function meant to check and set the status of that service. With a valid service status handle, Mail-O detaches the calling process from its console, changes the service status values to reflect its current running state, and calls the Entery function.
After a complete compromise of the infrastructure, the attackers proceeded to collect confidential information from all sources of interest... and workstations of various levels.
After a complete compromise of the infrastructure, the attackers proceeded to collect confidential information from all sources of interest: such as mail servers, electronic document management servers, file servers, and workstations of various levels.
It decrypts configuration strings and contacts https://dispatcher.cloud.mail.ru/ . Mail-O uses the SystemTime to POST the encrypted victim hostname (or in its absence the string “[none]”) and receive a payload.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader malware disguised to resemble legitimate Mail.ru Disk-O software. It checks for Mail.ru Disk-O installation, decrypts configuration strings, contacts dispatcher.cloud.mail.ru, posts encrypted victim host details, retrieves a next-stage payload, writes it to a temporary path, executes it, and then sleeps. It also exports ServiceMain and Entery and checks for %AllUsersProfile%PSEXESVC.EXE.
Downloader malware disguised to resemble legitimate Mail.ru Disk-O software. It checks for Mail.ru Disk-O installation, decrypts configuration strings, posts encrypted victim host details to dispatcher.cloud.mail.ru, retrieves a next-stage payload, writes it to a temporary path, executes it, and then sleeps. It also exports Entery and ServiceMain and checks for %AllUsersProfile%PSEXESVC.EXE.
A stealthy backdoor used after compromise to execute commands on infected hosts and steal confidential data. It exfiltrated data to command-and-control infrastructure via Mail.ru Cloud servers and was designed to bypass Kaspersky antivirus while disguising traffic as legitimate Mail.ru Disk-O communications.
Related implant variant referenced alongside WebDav-O; uses cloud platforms for command-and-control and data exfiltration with similar operational patterns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.