HATVIBE

First seen
2023-04-01 00:00:00
Malware type
backdoor
Last IoC activity
2026-07-21 16:30:13
Profile updated
2026-07-07 14:27:39

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Sekoia, the aim of this backdoor is to receive VBS modules for execution from a remote C2 server. Once received, HATVIBE uses a simple XOR algorithm to decrypt each module, contact it between two tags before adding it to the HTML body of the HTA file, leading to the automatic execution of the received module.

Reports & references

  • github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
  • recordedfuture.com — Russia Aligned Tag 110 Targets Tajikistan With Macro Enabled (report)
  • go.recordedfuture.com — Cta 2025 0522 (report)
  • malpedia.caad.fkie.fraunhofer.de — Vbs.Hatvibe (report)
  • go.recordedfuture.com — Cta Ru 2024 1121 (report)
  • bitdefender.com — Uac 0063 Cyber Espionage Operation Expanding From Central Asia (report)
  • blog.sekoia.io — Double Tap Campaign Russia Nexus Apt Possibly Related To Apt28 Conducts Cyber Espionage On Central Asia And Kazakhstan Diplomatic Relations (report)
  • CERT-UA — 6280129 (report)

External references