Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

FILEMESS

FILEMESS is a Go-based stealer used in Ukrainian-targeted campaigns, particularly those attributed by CERT-UA to UAC-0239. Since at least the second half of September 2025, it has been observed in spearphishing attacks against the Defence Forces of Ukraine and local government/state bodies across multiple Ukrainian regions, including campaigns impersonating the Security Service of Ukraine and using lure themes related to “countering russian sabotage-reconnaissance groups.” Delivery was observed via phishing emails sent from services such as UKR.net and Gmail, with links to password-protected archives or direct VHD attachments containing an executable and decoy PDF documents. FILEMESS was also reported alongside the OrcaC2 framework.

Its primary function is file theft. FILEMESS recursively searches for files matching targeted extensions in Desktop, Downloads, and Documents folders and on logical drives D through Z; reporting also notes that it collects files matching certain extensions and exfiltrates them to Telegram via the Telegram API. It computes MD5 hashes of discovered files, uses two extension lists including a shorter list for common user folders, checks for an existing process to avoid multiple concurrent instances, and establishes persistence through a Windows Registry Run key. Its Telegram API credentials are XOR-obfuscated and Base64-encoded. High-confidence associations in the provided content link FILEMESS to UAC-0239 campaigns targeting Ukrainian defense forces and local governments; no specific file hashes or network IoCs for FILEMESS itself were provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0239

14.10.2025 "Протидія російським ДРГ": UAC-0239 здійснює кібератаки з використанням фреймворку OrcaC2 та стілеру FILEMESS (CERT-UA#17691)

via cert uacert.gov.ua
ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.