Netskope Threat Labs

WellMail

ATP Sandbox Adv. HeuristicsAV
First seen
March 2022
Last seen
September 2026
Wellmail

9 techniques across 4 tactics.

TA0005 Stealth

  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery

TA0009 Collection

  • T1005Data from Local System
  • T1560Archive Collected Data

TA0011 Command and Control

Alert Name
Linux.Backdoor.WellMail
Linux.Trojan.WellMail
Trojan.Linux.Wellmail.A
Trojan.Linux.Wellmail.D
Trojan.Linux.Wellmail.E