Skip to content

Malware

OLDBAIT

aka Sasfis

According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28.

According to FireEye, OLDBAIT is a credential stealer that has been observed to be used by APT28. It targets Internet Explorer, Mozilla Firefox, Eudora, The Bat! (an email client by a Moldovan company), and Becky! (an email client made by a Japanese company). It can use both HTTP or SMTP to exfiltrate data. In some places it is mistakenly named "Sasfis", which however seems to be a completely different and unrelated malware family.


Family metadata imported from Malpedia (Fraunhofer FKIE).