Netskope Threat Labs

HALFBAKED

ATP Sandbox Adv. Heuristics

HALFBAKED is a backdoor tool that researchers associated with the APT29 threat group, which used it to survey victims, execute commands, and harvest credentials from compromised systems. The tool communicated with command and control servers through encrypted channels and supported in memory execution to avoid leaving artifacts on disk.

First seen
July 2022
Last seen
October 2026

6 techniques across 4 tactics.

TA0002 Execution

  • T1047Windows Management Instrumentation
  • T1059Command and Scripting Interpreter

TA0005 Stealth

TA0007 Discovery

  • T1057Process Discovery
  • T1082System Information Discovery

TA0009 Collection

Alert Name
Document-Word.Backdoor.Halfbaked