HATVIBE
- First seen
- 2023-04-01 00:00:00
- Malware type
- backdoor
- Last IoC activity
- 2026-07-21 16:30:13
- Profile updated
- 2026-07-07 14:27:39
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.
Reports & references
- github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
- recordedfuture.com — Russia Aligned Tag 110 Targets Tajikistan With Macro Enabled (report)
- go.recordedfuture.com — Cta 2025 0522 (report)
- malpedia.caad.fkie.fraunhofer.de — Vbs.Hatvibe (report)
- go.recordedfuture.com — Cta Ru 2024 1121 (report)
- bitdefender.com — Uac 0063 Cyber Espionage Operation Expanding From Central Asia (report)
- blog.sekoia.io — Double Tap Campaign Russia Nexus Apt Possibly Related To Apt28 Conducts Cyber Espionage On Central Asia And Kazakhstan Diplomatic Relations (report)
- CERT-UA — 6280129 (report)