Description
WellMess is a lightweight malware family with .NET and Golang variants that APT29 has used since at least 2018, and which came to wide attention during the 2020 investigations into intrusions against research and development organizations.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Also known as
Wellmess
MITRE ATT&CK techniques
15 techniques across 5 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.WellMess |
| Gen:Variant.Linux.Wellmess.1 |
| Gen:Variant.Trojan.Linux.Wellmess.1 |
| Linux.Spyware.WellMess |
| Linux.Trojan.WellMess |
| Win32.Trojan.WellMess |
| Win64.Trojan.WellMess |