JHUHUGIT
MITRE ATT&CK: S0044 View on attack.mitre.org
Aliases: Trojan.Sofacy, Seduploader, JKEYSKW, Sednit, GAMEFISH, SofacyCarberp, carberplike, downrage, jhuhugit, jkeyskw, JHUHUGIT
- First seen
- 2014-01-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 11 (5 malicious)
- Last IoC activity
- 2026-09-01 16:37:14
- Profile updated
- 2026-07-07 15:44:30
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Targeted regions: country_code:us country_code:fr country_code:de country_code:pl country_code:ru
Context
JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.
Recent IoC activity
5 malicious indicators in Maltiverse are attributed to JHUHUGIT (S0044). The 5 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | beatguitar.com | 2026-09-02 | 2 |
| file sample | EasySuiteSetup.msi | 2026-08-02 | 1 |
| file sample | KawaiiCraftLauncher Setup.msi | 2026-07-05 | 2 |
| file sample | 47929fb6916ac4f0f2b3249c5aa3c1a9 | 2026-04-20 | 1 |
| file sample | 8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109 | 2025-10-12 | 1 |
Detection coverage
- 2 YARA rules
- 358 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Fallback Channels (attack-pattern)
- Process Discovery (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Standard Encoding (attack-pattern)
- Web Protocols (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Logon Script (Windows) (attack-pattern)
- Clipboard Data (attack-pattern)
- Windows Command Shell (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Component Object Model Hijacking (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Windows Service (attack-pattern)
- Process Injection (attack-pattern)
- Rundll32 (attack-pattern)
- Local Storage Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Exploited vulnerabilities
- CVE-2017-11292 (vulnerability)
Detection rules
- CAPE_Seduploader (yara-rule)
- MALPEDIA_Win_Seduploader_Auto (yara-rule)
Related threat objects
- Komplex (malware)
Reports & references
- Kaspersky — 83930 (report)
- Broadcom/Symantec — Apt28 Espionage Military Government (report)
- CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
- Kaspersky — 72924 (report)
- researchcenter.paloaltonetworks.com — Unit42 New Sofacy Attacks Against Us Government Agency (report)
- Trend Micro — Wp Operation Pawn Storm (report)
- Cisco Talos — Cyber Conflict Decoy Document (report)
- Broadcom/Symantec — Apt28 Espionage Military Government (report)
- secureworks.com — Iron Twilight (report)
- contagiodump.blogspot.de — Russian Apt Apt28 Collection Of Samples (report)
- ESET — Eset Sednit Part1 (report)
- Mandiant — Apt28 Center Of Storm 2017 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Seduploader (report)
- blog.yoroi.company — Apt28 And Upcoming Elections Possible Interference Signals Part Ii (report)
- emanueledelucia.net — Apt28 Sofacy Seduploader Under The Christmas Tree (report)
- ESET — Sednit Apt Group Meets Hacking Team (report)
- Mandiant — Apt28 Targets Hospitality Sector (report)
- Cisco Talos — Cyber Conflict Decoy Document (report)
- Trend Micro — New Adobe Flash Zero Day Used In Pawn Storm Campaign (report)
- proofpoint.com — Apt28 Racing Exploit Cve 2017 11292 Flash Vulnerability Patches Are Deployed (report)
- blog.xpnsec.com — Apt28 Hospitality Malware Part 2 (report)
- ESET — Sednit Update Fancy Bear Spent Year (report)
- ESET — Sednit Adds Two Zero Day Exploits Using Trumps Attack Syria Decoy (report)
- MITRE ATT&CK — S0044 (report)
- labsblog.f-secure.com — Sofacy Recycles Carberp And Metasploit Code (report)
External references
- mitre-attack — S0044
- JHUHUGIT
- JKEYSKW
- GAMEFISH
- Seduploader
- SofacyCarberp
- ESET Sednit Part 1
- F-Secure Sofacy 2015
- FireEye APT28 January 2017
- Kaspersky Sofacy
- Unit 42 Sofacy Feb 2018
- Talos Seduploader Oct 2017
- Symantec APT28 Oct 2018
- Sednit
- Trojan.Sofacy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy