Also known as: APT28, Fancy Bear, Unknown Group 0002, tracked as, Zirconium, which the U.K, a milagro, miracle, Calomel, Pawn Storm, WestCare North Carolina, academic institutions, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, services, other system resources, public key cryptography, one private, the file association, header, Sednit, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, ZIRCONIUM, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412, TIDE CASTLE
HollowQuill, often conflated with or an alias of APT28, Sednit or the BO Team, conducts advanced threat campaigns that combine phishing, zero‑day exploitation and tailored payload delivery. Attacks commence with spear‑phishing emails that include double‑extension attachments (e.g., .pdf.scr, .rar.exe) masquerading as innocuous research invitations. Once executed, a .NET dropper—obfuscated with Themida or .NET Reactor—installs a lightweight Golang loader which then pulls the final payload from dynamic DNS C&C servers. The actor consistently uses anti‑forensics techniques: counterfeit icons, hidden files, and reflective DLL injection to keep code in memory. Persistence is achieved through scheduled tasks, Windows Management Instrumentation policies and WMI event subscriptions, while privilege escalation is performed via credential dumping with Mimikatz run from injected loaders or by injecting into trusted processes. HollowQuill also leverages exploitation of software vulnerabilities in the supply chain, such as XSS flaws in MDaemon email servers (CVE‑2024‑11182), Office CVE‑2012‑0158 and recent WebDAV exploits. In addition to delivering backdoors, the group routinely deploys ransomware families—including LockBit 3.0 and Babuk—once backups are destroyed or key credentials extracted. The adversary’s operations span dozens of countries (Russia, Ukraine, Taiwan, Israel, UAE, Colombia, Brazil, India, Australia, etc.) and target an array of public sector organizations, private enterprises, and critical infrastructures, often choosing victims that maximize symbolic or financial impact.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
HollowQuill is a financially‑motivated threat actor that targets a wide spectrum of sectors—financial, defense, education, energy and critical infrastructure—across multiple nations. The group delivers sophisticated spear‑phishing campaigns using malicious RAR/PDF attachments containing .NET droppers protected by Themida or .NET Reactor, then loads Golang‑based loaders and often a Cobalt Strike beacon. Their operations exhibit rapid deployment across diverse industries while leveraging dynamic DNS command‑and‑control infrastructure, zero‑day webmail exploits (e.g., MDaemon XSS CVE‑2024‑11182), and living‑off‑the‑land techniques to evade detection.
Goals & Targeting
HollowQuill’s primary objective is monetary gain, but their campaign design reveals a broader strategic goal: to coerce governments, defense contractors and vital utilities into paying for damage control, while using the stolen credentials to expand lateral reach. The targeting profile focuses on entities with high-value data (government emails, proprietary engineering designs, customer records) across varied sectors—including finance, telecoms, energy and aerospace—indicating an opportunistic approach that prioritizes financial returns over pure espionage. Their use of localized spear‑phishing subjects indicates a desire to infiltrate high‑trust organizations by exploiting human factors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
HollowQuill’s known campaigns exhibit a distinct pattern: phishing emails with malicious archive attachments are dispatched to multiple industries, followed by rapid deployment of a lightweight, obfuscated dropper that connects to dynamic DNS C&C servers. The group leverages both exploitation of public‐facing applications and living‑off‑the‑land tactics to maintain persistence and lateral movement. Operational tempo is high, with campaigns often overlapping or sharing infrastructure, suggesting strong internal coordination and resourcefulness. Victims range from academic institutions in the Baltics to defense contractors across Eastern Europe, Asia and the Americas, underscoring a broad geographic focus driven by financial objectives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The dataset combines observations from multiple advisories, security vendor reports and open‑source intelligence, yielding a solid but incomplete picture. While the recurring technical behavior, targeting sectors, and shared weaponization point to a single actor or closely linked groups, definitive attribution remains uncertain due to potential overlapping tools or misattributed incidents. Additionally, many operations are derived from public disclosures with limited disclosure of timeline and precise victim list, leaving gaps around exact operational cadence and financial outcomes.
No campaigns linked yet.
No observed data linked yet.
55
Techniques
67
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics