WellMail

S0515

Malware.View on attack.mitre.org

About this malware

WellMail is a lightweight malware written in Golang used by APT29, similar in design and structure to WellMess.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

WellMail can exfiltrate files from the victim machine.

T1016
System Network Configuration Discovery

WellMail can identify the IP address of the victim system.

T1033
System Owner/User Discovery

WellMail can identify the current username on the victim system.

T1095
Non-Application Layer Protocol

WellMail can use TCP for C2 communications.

T1105
Ingress Tool Transfer

WellMail can receive data and executable scripts from C2.

T1140
Deobfuscate/Decode Files or Information

WellMail can decompress scripts received from C2.

T1560
Archive Collected Data

WellMail can archive files on the compromised host.

T1571
Non-Standard Port

WellMail has been observed using TCP port 25, without using SMTP, to leverage an open port for secure command and control communications.

T1573.002
Asymmetric Cryptography

WellMail can use hard coded client and certificate authority certificates to communicate with C2 over mutual TLS.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CISA WellMail July 2020 Open source
    CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020.
  2. NCSC APT29 July 2020 Open source
    National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.