GraphSteel

Malware type
backdoor
Profile updated
2026-07-07 13:00:58

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Graphsteel_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Graphsteel (report)
  • CERT-UA — 38374 (report)
  • intezer.com — Elephant Malware Targeting Ukrainian Orgs (report)
  • sentinelone.com — Threat Actor Uac 0056 Targeting Ukraine With Fake Translation Software (report)
  • trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
  • inquest.net — Ukraine Cyberwar Overview (report)
  • cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
  • Mandiant — Spear Phish Ukrainian Entities (report)
  • cybercom.mil — Cyber National Mission Force Discloses Iocs From Ukrainian Networks (report)
  • secureworks.com — The Growing Threat From Infostealers (report)
  • govinfosecurity.com — Cyber Espionage Actor Deploying Malware Using Excel A 18830 (report)
  • businessinsights.bitdefender.com — Deep Dive Into The Elephant Framework A New Cyber Threat In Ukraine (report)

External references