WebDav-O is a stealthy Windows backdoor associated with cyber-espionage intrusions against government and government-linked organizations, including victims in Russia and Belarus. It has been linked in reporting to the CoughingDown cluster and discussed alongside related activity involving Mail-O and PhantomNet/SManager tooling. The malware has been used after successful compromise of victim environments, including cases where attackers exploited vulnerable IIS servers, and has also been associated with broader intrusion chains involving spearphishing, web application exploitation, and compromises of contractor infrastructure.
Its primary role is post-compromise remote access and data theft. WebDav-O enables operators to execute arbitrary commands on infected hosts, conduct reconnaissance, and exfiltrate collected information. A notable characteristic is its command-and-control design, which abuses legitimate cloud storage services for bidirectional communications and file exchange. Observed variants used Yandex Disk, and reporting also references abuse of Dropbox and Mail-related cloud services as part of the family’s communication methods. This cloud-service-based C2 helps the malware blend into normal network traffic and support covert exfiltration.
Operationally, WebDav-O has appeared in campaigns where attackers combined it with common Windows tradecraft for persistence, credential access, lateral movement, and defense evasion. Associated intrusions included malicious Windows service creation, masquerading under fake system-like filenames, WMI-based remote execution, SMB access, credential dumping, COM hijacking, and event log clearing. The malware has also been described as designed to evade Kaspersky antivirus and to mimic legitimate cloud application traffic, reinforcing its emphasis on stealth and long-term access.
WebDav-O is best characterized as a cloud-backed espionage backdoor used in targeted operations against public-sector entities. Its observed behavior centers on maintaining covert access, executing operator commands, and stealing data from compromised Windows environments while hiding communications within trusted cloud services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2022, our systems detected an attack employing malware known as WebDav-O that targeted a government agency in Russia.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
To get initial access to the victim, the attacking group exploited a vulnerability in IIS Windows Server.
After a complete compromise of the infrastructure, the attackers proceeded to collect confidential information from all sources of interest... and workstations of various levels.
After a complete compromise of the infrastructure, the attackers proceeded to collect confidential information from all sources of interest: such as mail servers, electronic document management servers, file servers, and workstations of various levels.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another malware component described elsewhere, but not analyzed in this content.
A stealthy backdoor used after compromise to execute commands on infected hosts and steal confidential data. It exfiltrated data to command-and-control infrastructure via Yandex.Disk and was designed to bypass Kaspersky antivirus while disguising traffic as legitimate Yandex.Disk application communications.
Backdoor/implant used for cyberespionage. It communicates with cloud services such as Yandex Disk to receive encrypted commands, upload/download files, and execute arbitrary shell commands on compromised hosts.
Implant family using cloud storage/web services for command-and-control and exfiltration; the Yandex variant supports upload, download, sleep control, and command execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.