Cisco Talos recently identified a large number of ongoing malware distribution campaigns linked to a threat actor we're calling "SWEED," including such notable malware as Formbook, Lokibot and Agent Tesla. Based on our research, SWEED — which has been operating since at least 2017 — primarily targets their victims with stealers and remote access trojans. SWEED remains consistent across most of their campaigns in their use of spear-phishing emails with malicious attachments. While these campaigns have featured a myriad of different types of malicious documents, the actor primarily tries to infect its victims with a packed version of Agent Tesla — an information stealer that's been around since at least 2014. The version of Agent Tesla that SWEED is using differs slightly from what we've seen in the past in the way that it is packed, as well as how it infects the system. In this post, we'll run down each campaign we're able to connect to SWEED, and talk about some of the actor's tactics, techniques and procedures (TTPs).
Executive Summary
The SWEED threat actor has been actively distributing malware campaigns since at least 2017, primarily targeting victims with information stealers like Formbook and Agent Tesla through spear-phishing emails. The actor is known for consistently using malicious attachments to deliver payloads, focusing on sectors such as retail and finance in the United States and European Union. SWEED's operations demonstrate a moderate level of sophistication, with a focus on stealing credentials and financial data.
Goals & Targeting
SWEED's primary objective appears to be the theft of sensitive information, including credentials and financial data, from targeted individuals and organizations. The actor's focus on retail and financial sectors suggests an interest in accessing personally identifiable information (PII) and financial records. By leveraging spear-phishing campaigns, SWEED aims to compromise end-users within target organizations, allowing for the deployment of remote access trojans and information stealers. The consistent use of malicious Office document attachments indicates a preference for methods that can bypass basic email filtering mechanisms while remaining somewhat stealthy.
Enhanced Description
SWEED has emerged as a persistent threat actor engaged in numerous malware distribution campaigns since at least 2017. The group primarily delivers information stealers such as Formbook, Lokibot, and Agent Tesla to its victims, often through sophisticated spear-phishing techniques involving malicious Office document attachments. While the campaigns have employed various methods of delivery, SWEED has consistently relied on malicious scripts packed within these documents to infect systems. The actor's use of custom packing techniques for Agent Tesla highlights a level of operational creativity, though the core methodology remains consistent across campaigns. SWEED's targeting focus appears to be on sectors with sensitive personal and financial data, such as retail and financial services, particularly in the United States and European Union.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SWEED has been involved in numerous campaigns targeting individuals and organizations across various industries, with a particular emphasis on sectors where sensitive information is stored. The consistent use of spear-phishing emails with malicious attachments suggests a deliberate operational strategy to maximize infection rates while minimizing detection. Campaigns have varied in their specific tactics but have remained true to the core methodology of delivering known malware families like Agent Tesla. Notable past operations include the distribution of Formbook and Lokibot, with campaigns often leveraging different malwares to evase detection. The actor's operational tempo appears steady, with ongoing activity observed across multiple years.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
There is a high level of confidence in the information regarding SWEED's activities and TTPs due to extensive research by Cisco Talos. However, gaps exist in understanding the full scope of the actor's infrastructure and long-term objectives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics