Netskope Threat Labs

JHUHUGIT

ATP Sandbox Adv. HeuristicsAV

JHUHUGIT (a.k.a. Sednit, Seduploader) is a downloader associated with the APT28 threat group that delivers additional malware payloads through scheduled tasks and process enumeration. It typically serves as a first stage in targeted espionage campaigns, surveying infected systems before pulling more capable implants. The family's long service in Russian state sponsored operations shows how lightweight initial access tools anchor sophisticated intrusions.

First seen
March 2022
Last seen
October 2026
SednitSeduploader

20 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1037Boot or Logon Initialization Scripts
  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation
  • T1546Event Triggered Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Trojan.Sednit
Dropped:Trojan.Sednit.13
Dropped:Trojan.Sednit.14
Dropped:Trojan.Sednit.16
Gen:Variant.Sednit.102
Gen:Variant.Sednit.23
Gen:Variant.Sednit.40
Gen:Variant.Sednit.62
Gen:Variant.Sednit.75
Gen:Variant.Sednit.78