HEADRUSH is a malicious Microsoft Excel add-in used by the suspected Russian-linked espionage cluster UNC5976. Observed in April 2026, it was delivered through infrastructure impersonating a Ukrainian research institute and was assessed as potentially targeting a Ukrainian aerospace and imaging company. HEADRUSH ultimately leads to an HTML Application downloader; the complete downstream infection chain has not been established. UNC5976 primarily targets military, aerospace, defense-industrial-base, NGO, and think-tank entities, with a particular focus on Ukraine and Armenia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In separate operations, UNC5976 deployed a malicious Excel add-in named HEADRUSH to compromise Ukrainian aerospace targets.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Excel add-in deployed by UNC5976 to compromise Ukrainian aerospace targets.
Malicious Excel add-in that leads to an HTA downloader as part of the intrusion chain.
Named malware/sample listed in the indicators; the content provides no further behavioral detail beyond its inclusion as a sample.
A malicious Excel plugin distributed by UNC5976 that leads to an HTA downloader as part of an incomplete infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.