Unidentified 099 (APT29 Dropbox Loader)

Malware type
loader
Profile updated
2026-07-07 14:48:42

Targeted industries: government-and-public-sector

Context

This malware uses DropBox for C2 and was spread via spear-phishing attack at government organizations. It is different from win.boombox, which is another APT29 attributed malware using DropBox (written in .NET).

Reports & references

  • incibe-cert.es — Incibe Cert Estudio Analisis Nobelium 2022 V1 (report)
  • incibe.es — Incibe Cert Estudio Analisis Nobelium 2022 V1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Unidentified 099 (report)
  • github.com — Apt29 Dropboxloader Analysis.Md (report)

External references