Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GOFFEE

Also known as: APT28, Paper Werewolf, Fancy Bear, tracked as, the Red planet, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Rezet, Unicorn, LAUNDRY BEAR, Bronze Elgin, UNC2596, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Stone Panda, Potassium, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, Red Apollo, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Cicada, Purple Typhoon, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM

Description

GOFFEE’s attack lifecycle begins with engineered spear‑phishing emails that exploit browser extensions or embed malicious JavaScript payloads targeting webmail clients such as Horde, MDaemon, Zimbra, and Roundcube. The attacker often leverages zero‑day vulnerabilities (e.g., CVE‑2024‑11182 and recent WinRAR exploits) to bypass defenses and deploy custom PowerShell‑based Mythic agents—PowerTaskel or the newer binary Implant, PowerModul—inside victim networks. Once inside, GOFFEE pushes a suite of backdoors (Havoc, HanifNet, MeshCentral Agent, SystemBC, Fast Reverse Proxy, Auto‑Color Linux) and often injects malicious VBA macros into Word documents to extend persistence. The group exhibits advanced lateral movement techniques, including reflection-based Java payload execution, credential harvesting from local MySQL files, and exploitation of Ivanti EPMM CVEs for remote code execution. GOFFEE consistently updates its toolchain to evade detection, using legitimate Windows utilities (iediagcmd.exe), HTTP tunneling services (Ngrok), and obfuscation such as steganography in payloads or packing via WinRAR. Their campaigns are frequently tied to geopolitical objectives but also yield significant financial gains through data exfiltration. Overall, GOFFEE remains a top threat actor with high attribution confidence due to the persistence of its unique artifacts (PowerModul implants, XSS webmail exploitation), and they continue to expand their attack surface across a broad range of sectors.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Manufacturing
Education
Healthcare
Energy
Transportation
Critical infrastructure
Media
Retail
Non profit
Aerospace
Aviation
Construction
Hospitality
Pharmaceutical
Utilities
Oil gas
Mining
Information technology
Think tank
Legal services
Entertainment
Chemical
Gaming
Nuclear
Food agriculture
Maritime

Targeted Countries / Regions

RU
US
CN
TW
VN
JP
IL
UA
AE
AU
BY
IR
SG
TR
KR
SA
CA
GB
PK
IN
BR
KZ
DE
MX
ES
PL
EG
RO
FR
NG
KP
IT
LB
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

GOFFEE—also known as APT28/Fancy Bear—is a highly sophisticated threat actor that has targeted Russian and numerous global organizations since early 2022. Employing spear‑phishing, webmail XSS exploits, zero‑day CVEs, and custom Mythic‑based implants (PowerTaskel, PowerModul), the group achieves persistence, lateral movement, and data exfiltration across sectors including government, defense, finance, and telecommunications.

Goals & Targeting

The actor’s strategic objectives combine state‑level intelligence gathering with financial exploitation. GOFFEE targets critical infrastructure, defense contractors, finance, telecommunications, and manufacturing firms worldwide, focusing on organizations in Russia, Ukraine, the United States, China, and other technologically relevant states. By compromising high‑value accounts (VPN, web browsers), they extract privileged credentials, exfiltrate sensitive data, and sometimes monetize through ransomware or sell stolen information. Beyond espionage, GOFFEE’s campaigns are known for their persistence in delivering payloads and maintaining long‑term footholds via Mythic‑based agents. Their focus on sectors that store proprietary research and supply‑chain details suggests a dual motive: direct financial gain from data resale and strategic intelligence benefits to adversary governments. GOFFEE employs a multi‑layered approach—phishing, webmail exploitation, zero‑day CVEs—to ensure high success rates, enabling them to pivot quickly between initial compromise, lateral movement, and exfiltration across diverse industry targets.

Enhanced Description

Key Capabilities

  • Spear‑phishing with embedded XSS payloads targeting webmail clients
  • Exploitation of webmail client vulnerabilities (Horde, MDaemon, Zimbra, Roundcube)
  • Zero‑day exploitation of widely used software (e.g., CVE‑2024‑11182, WinRAR CVEs)
  • Malicious JavaScript execution for email and contact harvesting
  • Deployment of custom backdoors and web shells (Havoc, HanifNet, MeshCentral Agent, SystemBC)
  • Remote code execution via Ivanti EPMM and other CVEs
  • Reflective Java payloads for in‑memory command execution
  • Extraction of hard‑coded MySQL credentials for lateral movement
  • Use of Fast Reverse Proxy and Auto‑Color Linux backdoor to maintain persistence
  • Utilization of legitimate Windows tools (iediagcmd.exe) for delivery
  • Delivery of custom implants via WebDAV or compressed archives
  • Phishing with spoofed emails and malicious attachments
  • .NET assemblies and in‑memory payload deployment
  • Targeted attacks against defense, finance, manufacturing, logistics companies

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Exfiltration

ATT&CK Techniques

T1113
T1056.001
T1176.001
T1115
T1005
T1055
T1016.002
T1555.003
T1217
T1497
T1059.001
T1547.001
T1678
T1685
T1027.003
T1012
T1046
T1566.002
T1203
T1059.006
T1078
T1021
T1041
T1566.001
T1190

Software / Tooling

ShadowPad
Mythic C2
Phishing
Sednit
Web Shells
Winnti
Cobalt Strike
Spearfishing
WinRAR
PowerShell
Dark
LockBit
Explorer
Anubis
Medusa
Interlock
Payload
Custom malware
Open-source tools
EchoGather
Global
Kimsuky
Naikon
PathWiper
Phantom Stealer
PhantomCore
PipeMagic
Void
ClickFix
Telegram
APT38
Gunra
Trojan
Subtle Snail
MuddyWater
SpyPress
KrustyLoader
Sliver
Havoc
HanifNet
HXLibrary
NeoExpressRAT
MeshCentral Agent
SystemBC
Fast Reverse Proxy (FRP)
Auto-Color Linux backdoor
Plink
Ngrok
Iediagcmd.exe
Horus Agent
PowerTaskel
PowerModul
SnipBot
RustyClaw
XPS Viewer

Campaigns & Victims

GOFFEE’s operations exhibit a rapid evolution in tactics and tools, with a clear preference for combining spear‑phishing, zero‑day exploits, and custom Mythic implants. The actor demonstrates an operational tempo that allows swift pivoting between high‑impact corporate targets and strategic defense firms across multiple continents. Frequent use of webmail XSS and WebDAV exploitation points to a well‑understood vector against enterprises with legacy or poorly patched mail infrastructures. Past campaigns—including the paper‑werewolf operation against Ukrainian firms and the Stealth Falcon assaults on Turkish defense—highlight GOFFEE’s ability to maintain persistence over months, leveraging encrypted C2 channels (Globe, Horus, Mythic) for data exfiltration. The group’s breadth of victim industries and continued innovation in payload delivery (reflection, VBA macros, WinRAR abuse) signals an ongoing threat of both espionage and financial theft.

IOC Patterns

  • CVE identifiers
  • XSS payloads detected in webmail client HTML
  • Phishing email subjects with political or sensational content
  • Web shell deployments on publicly accessible servers
  • Credential harvesting from VPN/SSL certificates
  • Compressed RAR archives disguised as legitimate documents
  • Spoofed sender addresses impersonating partner companies
  • Hash‑sha256 values for malicious binaries
  • Malicious file names targeting executables (e.g., H5GDXM70NJ.exe)
  • Domain indicators linked to command and control or dropper hosts
  • Email indicators of phishing campaigns

Recommended Actions

  • Apply vendor patches immediately for known CVEs (CVE‑2024‑11182, CVE‑2025‑33053, CVE‑2025‑8088, CVE‑2025‑6218).
  • Disable or strictly filter XSS in webmail applications and enforce strict MIME validation.
  • Deploy advanced email security solutions to detect spear‑phishing with malicious attachments and spoofed domains.
  • Block outbound traffic to known C2 IP ranges and monitor anomalous exfiltration attempts via encrypted tunnels.
  • Implement host‑based intrusion detection to flag the presence of Mythic agents, PowerTaskel, or PowerModul implants.
  • Segment networks and enforce least privilege to limit lateral movement from compromised accounts.
  • Use anti‑exploit solutions to detect reflective Java payloads and process injection attempts (T1055).
  • Enable logging of registry modifications (T1547.001) and monitor suspicious use of legitimate tools like iediagcmd.exe or rundll32 calls.
  • Conduct regular security awareness training focused on phishing, VBA macro abuse, and WebDAV exploitation.

Suggested Tags

APT28
Fancy Bear
Paper Werewolf
Stealth Falcon
GoffEE
SpearPhishing
XSSExploit
WebmailClientVulnerability
ZeroDayCVE
BackdoorDeployment
DataExfiltration
CommandAndControl
CredentialHarvesting
AdvancedPersistentThreat
DefenseSectorTargeting
IndustrialControlSystems
CyberEspionage

Confidence Assessment

The intelligence on GOFFEE is derived from multiple public reports and technical analyses, providing strong attribution indicators such as unique Mythic implants and consistent use of specific webmail XSS vectors. Confidence in actor identification, attack methodology, and toolset is high (>80%). However, gaps remain regarding the full spectrum of financial motivations, precise operational timelines, and the extent of undisclosed zero‑day assets. Continuous monitoring for emerging CVEs and new implant variants is recommended to close remaining uncertainty.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 8 IPv4 Address 1 SHA-256 Hash 2 Domain 9

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  3. www.splunk.com — Cited by web research for: T1027.003
  4. attack.mitre.org — Cited by web research for: Kimsuky
  5. securelist.com — Cited by web research for: Dark
  6. intezer.com — Cited by web research for: Stone Panda
  7. https://www.broadcom.com/support/security-center/protection-bulletin/paper-werewolf-campaign-delivering-echogather-malware — Cited by AI analysis.

Intel Summary

25

Techniques

65

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
APT
Espionage
Russia-Targeting
Media-Sector
Telecom-Sector
Government-Sector
APT28
Fancy Bear
Paper Werewolf
Stealth Falcon
GoffEE
SpearPhishing
XSSExploit
WebmailClientVulnerability
ZeroDayCVE
BackdoorDeployment
DataExfiltration
CommandAndControl
CredentialHarvesting
AdvancedPersistentThreat
DefenseSectorTargeting
IndustrialControlSystems
CyberEspionage

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.