GrimPlant
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:01:01
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
This malware was seen during the cyberattacks on Ukrainian state organizations. It is one of two used backdoors written in Go and attributed to UAC-0056 (SaintBear, UNC2589, TA471).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Grimplant_Auto (yara-rule)
Reports & references
- CERT-UA — 38374 (report)
- blog.malwarebytes.com — New Uac 0056 Activity Theres A Go Elephant In The Room (report)
- intezer.com — Elephant Malware Targeting Ukrainian Orgs (report)
- sentinelone.com — Threat Actor Uac 0056 Targeting Ukraine With Fake Translation Software (report)
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- inquest.net — Ukraine Cyberwar Overview (report)
- cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
- Mandiant — Spear Phish Ukrainian Entities (report)
- cybercom.mil — Cyber National Mission Force Discloses Iocs From Ukrainian Networks (report)
- govinfosecurity.com — Cyber Espionage Actor Deploying Malware Using Excel A 18830 (report)
- businessinsights.bitdefender.com — Deep Dive Into The Elephant Framework A New Cyber Threat In Ukraine (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Grimplant (report)