Netskope Threat Labs

WellMess

ATP Sandbox Adv. HeuristicsAV

WellMess is a lightweight malware family with .NET and Golang variants that APT29 has used since at least 2018, and which came to wide attention during the 2020 investigations into intrusions against research and development organizations.

First seen
March 2022
Last seen
September 2026
Wellmess

15 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

  • T1140Deobfuscate/Decode Files or Information

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1033System Owner/User Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Trojan.WellMess
Gen:Variant.Linux.Wellmess.1
Gen:Variant.Trojan.Linux.Wellmess.1
Linux.Spyware.WellMess
Linux.Trojan.WellMess
Win32.Trojan.WellMess
Win64.Trojan.WellMess