ENGINELIGHT is a Go-based malware family associated with the Russia-linked espionage cluster UNC7005, also tracked as STORM-2945 and linked to ICE RELIC/APT29. It has been observed as part of limited 2026 operations connected to the same infrastructure used in UNC7005 phishing and captive-portal activity. The broader UNC7005 intrusion set targeted individuals in academia, aerospace, defense, government, and think tanks in Europe and the United States, using social-engineering-heavy operations centered on account compromise and selective malware deployment. ENGINELIGHT is notable primarily for its use within this espionage ecosystem and for command-and-control communications tied to UNC7005 infrastructure. High-confidence reporting supports its classification as malware used in support of targeted espionage operations, but the available information does not establish a more specific functional profile such as infostealer, loader, or remote-access trojan.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Domain statistic-ms.live UNC7005 ENGINELIGHT command-and-control domain
Domain statistic-ms.live UNC7005 ENGINELIGHT command-and-control domain
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based malware communicating with C2 infrastructure at statistic-ms.live, used in the described Russian-linked espionage activity.
Named malware/tool associated with UNC7005 infrastructure; the content only specifies a command-and-control domain tied to ENGINELIGHT.
A Go-based malware used in a limited UNC7005 operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.