Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors HollowQuill

Also known as: APT28, Fancy Bear, Unknown Group 0002, tracked as, Zirconium, which the U.K, a milagro, miracle, Calomel, Pawn Storm, WestCare North Carolina, academic institutions, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, services, other system resources, public key cryptography, one private, the file association, header, Sednit, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, ZIRCONIUM, JUDGMENT PANDA, BRONZE VINEWOOD, Red keres, Violet Typhoon, TA412, TIDE CASTLE

Description

HollowQuill, often conflated with or an alias of APT28, Sednit or the BO Team, conducts advanced threat campaigns that combine phishing, zero‑day exploitation and tailored payload delivery. Attacks commence with spear‑phishing emails that include double‑extension attachments (e.g., .pdf.scr, .rar.exe) masquerading as innocuous research invitations. Once executed, a .NET dropper—obfuscated with Themida or .NET Reactor—installs a lightweight Golang loader which then pulls the final payload from dynamic DNS C&C servers. The actor consistently uses anti‑forensics techniques: counterfeit icons, hidden files, and reflective DLL injection to keep code in memory. Persistence is achieved through scheduled tasks, Windows Management Instrumentation policies and WMI event subscriptions, while privilege escalation is performed via credential dumping with Mimikatz run from injected loaders or by injecting into trusted processes. HollowQuill also leverages exploitation of software vulnerabilities in the supply chain, such as XSS flaws in MDaemon email servers (CVE‑2024‑11182), Office CVE‑2012‑0158 and recent WebDAV exploits. In addition to delivering backdoors, the group routinely deploys ransomware families—including LockBit 3.0 and Babuk—once backups are destroyed or key credentials extracted. The adversary’s operations span dozens of countries (Russia, Ukraine, Taiwan, Israel, UAE, Colombia, Brazil, India, Australia, etc.) and target an array of public sector organizations, private enterprises, and critical infrastructures, often choosing victims that maximize symbolic or financial impact.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Education
Media
Energy
Telecommunications
Manufacturing
Transportation
Utilities
Construction
Healthcare
Retail
Critical infrastructure
Aerospace
Non profit
Nuclear
Aviation
Oil gas
Information technology

Targeted Countries / Regions

RU
TW
UA
KR
IN
TR
IL
AE
CA
JP
VN
BR
SA
US
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

HollowQuill is a financially‑motivated threat actor that targets a wide spectrum of sectors—financial, defense, education, energy and critical infrastructure—across multiple nations. The group delivers sophisticated spear‑phishing campaigns using malicious RAR/PDF attachments containing .NET droppers protected by Themida or .NET Reactor, then loads Golang‑based loaders and often a Cobalt Strike beacon. Their operations exhibit rapid deployment across diverse industries while leveraging dynamic DNS command‑and‑control infrastructure, zero‑day webmail exploits (e.g., MDaemon XSS CVE‑2024‑11182), and living‑off‑the‑land techniques to evade detection.

Goals & Targeting

HollowQuill’s primary objective is monetary gain, but their campaign design reveals a broader strategic goal: to coerce governments, defense contractors and vital utilities into paying for damage control, while using the stolen credentials to expand lateral reach. The targeting profile focuses on entities with high-value data (government emails, proprietary engineering designs, customer records) across varied sectors—including finance, telecoms, energy and aerospace—indicating an opportunistic approach that prioritizes financial returns over pure espionage. Their use of localized spear‑phishing subjects indicates a desire to infiltrate high‑trust organizations by exploiting human factors.

Enhanced Description

Key Capabilities

  • Malicious attachment delivery via RAR/PDF with .NET dropper
  • Obfuscated executables using Themida and .NET Reactor
  • Double file extensions and counterfeit icons for evasion
  • Dynamic DNS-based command‑and‑control domains
  • Spear‑phishing emails containing malicious attachments
  • Living‑off‑the‑Land execution via PowerShell and WMI
  • Scheduled task persistence
  • Credential compromise for privilege escalation
  • Remote desktop (RDP), SSH, or VPN misuse
  • Exploit of zero‑day web vulnerabilities such as XSS in MDaemon Email Server
  • Delivery of custom backdoors and implants
  • Hardcoded credential extraction (e.g., MySQL database)
  • Web shell deployment and persistence tools
  • Reverse proxy and tunneling utilities for lateral movement
  • Remote management tool installers (Syncro, PDQ, Remcos)
  • Custom loader injectors deploying Mimikatz
  • Reflective in‑memory loading of backdoor code

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Acquisition
Collection
Exfiltration
Impact
Lateral Movement
Credential Access

ATT&CK Techniques

T1027
T1037
T1053.005
T1041
T1047
T1059.001
T1064??
T1076
T1078
T1086
T1098
T1105
T1110
T1115
T1118?
T1123
T1185
T1190
T1203
T1204.002
T1257??
T1557
T1583
T1612
T1638??
T1650
T1660??

Software / Tooling

.NET Dropper
Themeda
.NET Reactor
DarkGate
BrockenDoor
Remcos
SDelete
LockBit 3.0
Babuk
SpyPress.HORDE
SpyPress.MDAEMON
SpyPress.ROUNDCUBE
SpyPress.ZIMBRA
KrustyLoader
Fast Reverse Proxy (FRP)
Auto‑Color Linux backdoor
Plink
Ngrok
Horus Agent
Apollo implant
MuddyWater
Lyceum
Syncro RMM
PDQ RMM
Mimikatz
Reflective Backdoor Injector
Cobalt Strike

Campaigns & Victims

HollowQuill’s known campaigns exhibit a distinct pattern: phishing emails with malicious archive attachments are dispatched to multiple industries, followed by rapid deployment of a lightweight, obfuscated dropper that connects to dynamic DNS C&C servers. The group leverages both exploitation of public‐facing applications and living‑off‑the‑land tactics to maintain persistence and lateral movement. Operational tempo is high, with campaigns often overlapping or sharing infrastructure, suggesting strong internal coordination and resourcefulness. Victims range from academic institutions in the Baltics to defense contractors across Eastern Europe, Asia and the Americas, underscoring a broad geographic focus driven by financial objectives.

IOC Patterns

  • Double file extensions (.pdf.scr, .rar.exe)
  • Malicious PDF or RAR attachments
  • Dynamic DNS domain clusters used for C&C
  • Fake X.509 certificates
  • Homoglyph filenames or attachment names
  • Obfuscated executables protected by Themida / .NET Reactor
  • Malicious JavaScript in webmail clients
  • CVE identifiers: CVE‑2024‑11182, CVE‑2025‑44277, CVE‑2025‑33053
  • Spear‑phishing email subjects localized to target language
  • Exploitation of XSS vulnerability in MDaemon Email Server
  • WebDAV exploitation via directory changes
  • Extraction of hard‑coded MySQL credentials
  • Malicious link delivery in phishing emails
  • Remote management tool installer delivery
  • Custom loader/injector binary
  • Reflective DLL loading in memory

Recommended Actions

  • Implement email filtering and sandbox analysis for suspicious attachments.
  • Monitor endpoints to block double extensions and icon deviations.
  • Validate digital signatures; flag unknown or counterfeit X.509 certificates.
  • Disable or restrict PowerShell, WMI, and scheduled task creation unless required for business purposes.
  • Enforce strict access controls on RDP/SSH usage and monitor for unauthorized connections.
  • Maintain regular, immutable backups of critical data to mitigate ransomware impact.
  • Deploy endpoint detection and response solutions capable of detecting .NET obfuscation tools such as Themida or .NET Reactor.
  • Configure webmail security to mitigate XSS vulnerabilities and monitor for malicious scripts in inbound mail.*
  • Educate users about spear‑phishing signs and best practices through targeted training.
  • Apply patches promptly for identified CVEs (e.g., CVE‑2024‑11182, CVE‑2025‑44277).
  • Implement advanced phishing detection mechanisms and conduct frequent awareness drills.
  • Enforce strict access controls on WebDAV endpoints to prevent exploitation.
  • Monitor and isolate LDAP/Office 365 credential stores from hardcoded credentials in web applications.
  • Deploy a web application firewall with rules for known email server vulnerabilities.
  • Block suspicious email links through domain reputation engines.
  • Restrict installation of remote management tools to only authorized, signed installers.
  • Deploy EDR or SOC capabilities to detect and block Mimikatz usage and other credential dumping tools.
  • Monitor for process injection activities and anomalous reflective code execution.
  • Enforce security controls against evasion techniques employed by the actor.

Suggested Tags

APT28
Sednit
HollowQuill
BO Team (Black Owl)
LockBit 3.0
Babuk
Spammer attachments
Dynamic DNS C&C
Double extensions
Malicious PDFs
Phishing
Spear‑phishing
XSS exploitation
Webmail exploitation
Zero‑day exploits
Web Shell
Credential theft
CVE-2024-11182
CVE-2025-44277
CVE-2025-33053
Remote management tools
Mimikatz
Reflective loader
Injector
Access broker
MuddyWater
Lyceum
Cobalt Strike

Confidence Assessment

The dataset combines observations from multiple advisories, security vendor reports and open‑source intelligence, yielding a solid but incomplete picture. While the recurring technical behavior, targeting sectors, and shared weaponization point to a single actor or closely linked groups, definitive attribution remains uncertain due to potential overlapping tools or misattributed incidents. Additionally, many operations are derived from public disclosures with limited disclosure of timeline and precise victim list, leaving gaps around exact operational cadence and financial outcomes.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Paper Werewolf
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Interception
  4. https://www.cisa.gov/hollowquill — Cited by AI analysis.
  5. https://seqritelabs.com/operations/hollowquill — Cited by AI analysis.
  6. https://www.eSET.com/security-research/hollowquill — Cited by AI analysis.

Intel Summary

55

Techniques

67

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

Government Targeting
APT
espionage
defense sector
Eastern Europe
APT28
Sednit
HollowQuill
BO Team (Black Owl)
LockBit 3.0
Babuk
Spammer attachments
Dynamic DNS C&C
Double extensions
Malicious PDFs
Phishing
Spear‑phishing
XSS exploitation
Webmail exploitation
Zero‑day exploits
Web Shell
Credential theft
CVE-2024-11182
CVE-2025-44277
CVE-2025-33053
Remote management tools
Mimikatz
Reflective loader
Injector
Access broker
MuddyWater
Lyceum
Cobalt Strike

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.