CredoMap
- First seen
- 2018-04-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:21:36
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
CredoMap is a credential-stealing malware used in targeted attacks primarily against Ukrainian government entities. It is often delivered via phishing emails and has been attributed to state-sponsored threat actors.
Reports & references
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
- blog.bushidotoken.net — Overview Of Russian Gru And Svr (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Credomap (report)
- CERT-UA — 341128 (report)
- securityscorecard.com — Apt28S Stealer Called Credomap (report)
- cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)