Skip to content

Malware

OLDBAIT

aka Sasfis

According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28.

OLDBAIT, also known as Sasfis, is a Windows malware family operated by APT28.

Background

FireEye describes OLDBAIT as a credential-harvesting tool linked to APT28 activity. The malware pulls stored credentials from Internet Explorer, Mozilla Firefox, Eudora, The Bat! (an email client from a Moldovan company), and Becky! (a Japanese email client), and can send the stolen data out over either HTTP or SMTP. The label "Sasfis" is sometimes applied to it by mistake, even though that appears to refer to an entirely separate, unrelated family.


Source: Malpedia (Fraunhofer FKIE).