JHUHUGIT

MITRE ATT&CK: S0044 View on attack.mitre.org

Aliases: Trojan.Sofacy, Seduploader, JKEYSKW, Sednit, GAMEFISH, SofacyCarberp, carberplike, downrage, jhuhugit, jkeyskw, JHUHUGIT

First seen
2014-01-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Related IoCs
11 (5 malicious)
Last IoC activity
2026-09-01 16:37:14
Profile updated
2026-07-07 15:44:30

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Targeted regions: country_code:us country_code:fr country_code:de country_code:pl country_code:ru

Context

JHUHUGIT is malware used by APT28. It is based on Carberp source code and serves as reconnaissance malware.

Recent IoC activity

5 malicious indicators in Maltiverse are attributed to JHUHUGIT (S0044). The 5 most recently updated:

TypeIndicatorUpdatedSources
hostname beatguitar.com 2026-09-02 2
file sample EasySuiteSetup.msi 2026-08-02 1
file sample KawaiiCraftLauncher Setup.msi 2026-07-05 2
file sample 47929fb6916ac4f0f2b3249c5aa3c1a9 2026-04-20 1
file sample 8f0674cb85f28b2619a6e0ddc74ce71e92ce4c3162056ef65ff2777104d20109 2025-10-12 1

Detection coverage

  • 2 YARA rules
  • 358 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Web Protocols (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Logon Script (Windows) (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Windows Service (attack-pattern)
  • Process Injection (attack-pattern)
  • Rundll32 (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2017-11292 (vulnerability)

Detection rules

  • CAPE_Seduploader (yara-rule)
  • MALPEDIA_Win_Seduploader_Auto (yara-rule)

Related threat objects

Reports & references

  • Kaspersky — 83930 (report)
  • Broadcom/Symantec — Apt28 Espionage Military Government (report)
  • CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
  • Kaspersky — 72924 (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Sofacy Attacks Against Us Government Agency (report)
  • Trend Micro — Wp Operation Pawn Storm (report)
  • Cisco Talos — Cyber Conflict Decoy Document (report)
  • Broadcom/Symantec — Apt28 Espionage Military Government (report)
  • secureworks.com — Iron Twilight (report)
  • contagiodump.blogspot.de — Russian Apt Apt28 Collection Of Samples (report)
  • ESET — Eset Sednit Part1 (report)
  • Mandiant — Apt28 Center Of Storm 2017 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Seduploader (report)
  • blog.yoroi.company — Apt28 And Upcoming Elections Possible Interference Signals Part Ii (report)
  • emanueledelucia.net — Apt28 Sofacy Seduploader Under The Christmas Tree (report)
  • ESET — Sednit Apt Group Meets Hacking Team (report)
  • Mandiant — Apt28 Targets Hospitality Sector (report)
  • Cisco Talos — Cyber Conflict Decoy Document (report)
  • Trend Micro — New Adobe Flash Zero Day Used In Pawn Storm Campaign (report)
  • proofpoint.com — Apt28 Racing Exploit Cve 2017 11292 Flash Vulnerability Patches Are Deployed (report)
  • blog.xpnsec.com — Apt28 Hospitality Malware Part 2 (report)
  • ESET — Sednit Update Fancy Bear Spent Year (report)
  • ESET — Sednit Adds Two Zero Day Exploits Using Trumps Attack Syria Decoy (report)
  • MITRE ATT&CK — S0044 (report)
  • labsblog.f-secure.com — Sofacy Recycles Carberp And Metasploit Code (report)

External references