WellMail — Malware Profile
WellMail is a lightweight malware written in Golang used by APT29, similar in design and structure to WellMess.
MITRE ATT&CK techniques (9)
- T1005 Data from Local System
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1140 Deobfuscate/Decode Files or Information
- T1560 Archive Collected Data
- T1571 Non-Standard Port
- T1573.002 Asymmetric Cryptography