Also known as: APT28, Paper Werewolf, Fancy Bear, tracked as, the Red planet, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Rezet, Unicorn, LAUNDRY BEAR, Bronze Elgin, UNC2596, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Stone Panda, Potassium, STONE PANDA, Menupass Team, happyyongzi, POTASSIUM, Red Apollo, CVNX, HOGFISH, Cloud Hopper, BRONZE RIVERSIDE, ATK41, G0045, Granite Taurus, TA429, Cicada, Purple Typhoon, IMPERIAL KITTEN, Yellow Liderc, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM
GOFFEE’s attack lifecycle begins with engineered spear‑phishing emails that exploit browser extensions or embed malicious JavaScript payloads targeting webmail clients such as Horde, MDaemon, Zimbra, and Roundcube. The attacker often leverages zero‑day vulnerabilities (e.g., CVE‑2024‑11182 and recent WinRAR exploits) to bypass defenses and deploy custom PowerShell‑based Mythic agents—PowerTaskel or the newer binary Implant, PowerModul—inside victim networks. Once inside, GOFFEE pushes a suite of backdoors (Havoc, HanifNet, MeshCentral Agent, SystemBC, Fast Reverse Proxy, Auto‑Color Linux) and often injects malicious VBA macros into Word documents to extend persistence. The group exhibits advanced lateral movement techniques, including reflection-based Java payload execution, credential harvesting from local MySQL files, and exploitation of Ivanti EPMM CVEs for remote code execution. GOFFEE consistently updates its toolchain to evade detection, using legitimate Windows utilities (iediagcmd.exe), HTTP tunneling services (Ngrok), and obfuscation such as steganography in payloads or packing via WinRAR. Their campaigns are frequently tied to geopolitical objectives but also yield significant financial gains through data exfiltration. Overall, GOFFEE remains a top threat actor with high attribution confidence due to the persistence of its unique artifacts (PowerModul implants, XSS webmail exploitation), and they continue to expand their attack surface across a broad range of sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GOFFEE—also known as APT28/Fancy Bear—is a highly sophisticated threat actor that has targeted Russian and numerous global organizations since early 2022. Employing spear‑phishing, webmail XSS exploits, zero‑day CVEs, and custom Mythic‑based implants (PowerTaskel, PowerModul), the group achieves persistence, lateral movement, and data exfiltration across sectors including government, defense, finance, and telecommunications.
Goals & Targeting
The actor’s strategic objectives combine state‑level intelligence gathering with financial exploitation. GOFFEE targets critical infrastructure, defense contractors, finance, telecommunications, and manufacturing firms worldwide, focusing on organizations in Russia, Ukraine, the United States, China, and other technologically relevant states. By compromising high‑value accounts (VPN, web browsers), they extract privileged credentials, exfiltrate sensitive data, and sometimes monetize through ransomware or sell stolen information. Beyond espionage, GOFFEE’s campaigns are known for their persistence in delivering payloads and maintaining long‑term footholds via Mythic‑based agents. Their focus on sectors that store proprietary research and supply‑chain details suggests a dual motive: direct financial gain from data resale and strategic intelligence benefits to adversary governments. GOFFEE employs a multi‑layered approach—phishing, webmail exploitation, zero‑day CVEs—to ensure high success rates, enabling them to pivot quickly between initial compromise, lateral movement, and exfiltration across diverse industry targets.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOFFEE’s operations exhibit a rapid evolution in tactics and tools, with a clear preference for combining spear‑phishing, zero‑day exploits, and custom Mythic implants. The actor demonstrates an operational tempo that allows swift pivoting between high‑impact corporate targets and strategic defense firms across multiple continents. Frequent use of webmail XSS and WebDAV exploitation points to a well‑understood vector against enterprises with legacy or poorly patched mail infrastructures. Past campaigns—including the paper‑werewolf operation against Ukrainian firms and the Stealth Falcon assaults on Turkish defense—highlight GOFFEE’s ability to maintain persistence over months, leveraging encrypted C2 channels (Globe, Horus, Mythic) for data exfiltration. The group’s breadth of victim industries and continued innovation in payload delivery (reflection, VBA macros, WinRAR abuse) signals an ongoing threat of both espionage and financial theft.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on GOFFEE is derived from multiple public reports and technical analyses, providing strong attribution indicators such as unique Mythic implants and consistent use of specific webmail XSS vectors. Confidence in actor identification, attack methodology, and toolset is high (>80%). However, gaps remain regarding the full spectrum of financial motivations, precise operational timelines, and the extent of undisclosed zero‑day assets. Continuous monitoring for emerging CVEs and new implant variants is recommended to close remaining uncertainty.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
65
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics