EnvyScout

Malware updated 5 months ago (2024-05-04T20:51:36.311Z)
Download STIX
Preview STIX
EnvyScout is a sophisticated malware used primarily by the threat actor group NOBELIUM, also known as APT29 or Cozy Bear. This malware, tracked by Microsoft and alternatively referred to as Rootsaw, is delivered via spear-phishing emails, often disguised with seemingly harmless attachments such as the NV.html file. Once opened, EnvyScout acts as a malicious dropper, de-obfuscating and writing a harmful ISO file to disk. It contains a payload stored as an encoded blob, which can further infect the target's system. The malware has been seen to drop downloaders like SNOWYAMBER and QUARTERRIG, which deliver additional payloads including the HALFRIG tool. In April, the Polish CERT and Military Counterintelligence Service issued a warning about an APT29 campaign that leveraged EnvyScout to target diplomats associated with NATO and the European Union. Notably, one of the phishing campaigns involved sending emails with the alleged 2023 schedule for the Polish ambassador to the U.S., carrying the EnvyScout malware. When the recipient opens the attached NV.img file (dropped by EnvyScout), it triggers the default behavior on Windows 10 to mount the ISO image at the next available drive letter, leading to system infection. The operation of EnvyScout involves several technical nuances. In some instances, the malware was observed to enumerate the executing browser’s environment, using the user-agent to determine whether a Windows machine received an ISO payload. In other iterations, EnvyScout contained execution guardrails wherein window.location.pathname was called, and its values were leveraged to ensure specific entries in the array of characters returned. The final component of EnvyScout is a short code snippet responsible for decoding the ISO in the Base64 encoded/XOR’d blob, and saving it to disk as NV.img with a mime type of “application/octet-stream”. This illustrates the complexity and adaptability of this malicious software.
Description last updated: 2024-03-25T10:15:38.425Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Dropper
Malware
Phishing
Payload
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The NOBELIUM Threat Actor is associated with EnvyScout. Nobelium, a threat actor linked to Russia, has been identified as a significant cybersecurity concern due to its persistent and sophisticated cyber-espionage campaigns. Known also by various other names such as APT29, Cozy Bear, Midnight Blizzard, and The Dukes, Nobelium is believed to be operating Unspecified
4
The APT29 Threat Actor is associated with EnvyScout. APT29, also known as Cozy Bear, Midnight Blizzard, Nobelium, and the Dukes, is a Russia-linked threat actor associated with SVR. This group is notorious for its sophisticated cyber espionage tactics, techniques, and procedures. APT29 often uses The Onion Router (TOR) network, leased and compromised Unspecified
4