Description
JHUHUGIT (a.k.a. Sednit, Seduploader) is a downloader associated with the APT28 threat group that delivers additional malware payloads through scheduled tasks and process enumeration. It typically serves as a first stage in targeted espionage campaigns, surveying infected systems before pulling more capable implants. The family's long service in Russian state sponsored operations shows how lightweight initial access tools anchor sophisticated intrusions.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
SednitSeduploader
MITRE ATT&CK techniques
20 techniques across 7 tactics.
TA0002 Execution
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Sednit |
| Dropped:Trojan.Sednit.13 |
| Dropped:Trojan.Sednit.14 |
| Dropped:Trojan.Sednit.16 |
| Gen:Variant.Sednit.102 |
| Gen:Variant.Sednit.23 |
| Gen:Variant.Sednit.40 |
| Gen:Variant.Sednit.62 |
| Gen:Variant.Sednit.75 |
| Gen:Variant.Sednit.78 |