CredoMap

First seen
2018-04-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Profile updated
2026-07-07 14:21:36

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

CredoMap is a credential-stealing malware used in targeted attacks primarily against Ukrainian government entities. It is often delivered via phishing emails and has been attributed to state-sponsored threat actors.

Reports & references

  • trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
  • github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
  • blog.bushidotoken.net — Overview Of Russian Gru And Svr (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Credomap (report)
  • CERT-UA — 341128 (report)
  • securityscorecard.com — Apt28S Stealer Called Credomap (report)
  • cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)

External references