Masepie

Malware updated 5 months ago (2024-05-04T18:19:15.905Z)
Download STIX
Preview STIX
MASEPIE is a malicious software (malware) first discovered in December 2023, which is capable of establishing persistence on Windows machines and executing arbitrary commands. It is described as a small Python backdoor that enables the downloading and uploading of files. When victims click to view lure documents on attacker-controlled sites, they download this backdoor. One of the files MASEPIE downloads to infected machines is "Oceanmap," a C#-based tool for command execution via the Internet Message Access Protocol (IMAP). Another payload associated with this campaign is "Steelhook," which has information-stealing functionality. The malware was directed by a botnet based on compromised Ubiquiti routers, evidence suggests that both the WebDAV servers and the MASEPIE C2 servers may have been hosted on these compromised routers. This botnet was taken down by the U.S. government in early 2024. Advanced Persistent Threat group APT28 targeted Ukrainian government entities and Polish organizations using phishing messages designed to deploy bespoke implants and information stealers like MASEPIE, OCEANMAP, and STEELHOOK. APT28’s elaborate scheme ends with the execution of MASEPIE, OCEANMAP, and STEELHOOK, which are designed to exfiltrate files, run arbitrary commands, and steal browser data. In an update to their methodologies, ITG05 is utilizing the freely available hosting provider, firstcloudit[.]com to stage payloads to enable ongoing operations. The cybersecurity researchers Joe Fasulo, Claire Zaboeva, and Golo Mühr have been closely following and analyzing these developments.
Description last updated: 2024-05-04T17:49:37.009Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
OCEANMAP is a possible alias for Masepie. OceanMap is a C#-based malware used by APT28, a Russia-linked group, as part of a sophisticated cyber attack campaign that started in 2020. The malware is designed to execute base64-encoded commands via cmd.exe, providing persistent and remote access to the targeted endpoint. Once a command is execu
3
Steelhook is a possible alias for Masepie. Steelhook is a malicious PowerShell script used by the Russia-linked Advanced Persistent Threat group, APT28, to steal sensitive information from compromised systems. The malware was discovered as part of a phishing campaign orchestrated by APT28, as reported by the Computer Emergency Response Team
3
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Windows
Decoy
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Masepie Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
7 months ago
CERT-EU
8 months ago
CERT-EU
7 months ago
CERT-EU
8 months ago
CERT-EU
10 months ago
BankInfoSecurity
10 months ago
CERT-EU
10 months ago
Securityaffairs
10 months ago
CERT-EU
10 months ago
CERT-EU
8 months ago
CERT-EU
8 months ago
DARKReading
7 months ago
CERT-EU
7 months ago