EnvyScout

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[EnvyScout](https://attack.mitre.org/software/S0634) is a dropper that has been used by [APT29](https://attack.mitre.org/groups/G0016) since at least 2021.(Citation: MSTIC Nobelium Toolset May 2021)

Associated Techniques (14)
ID ATT&CK Tactics
T1005 Data from Local System -
T1027.006 HTML Smuggling -
T1027.013 Encrypted/Encoded File -
T1036 Masquerading -
T1059.003 Windows Command Shell -
T1059.007 JavaScript -
T1082 System Information Discovery -
T1140 Deobfuscate/Decode Files or Information -
T1187 Forced Authentication -
T1204.002 Malicious File -
T1218.011 Rundll32 -
T1480 Execution Guardrails -
T1564.001 Hidden Files and Directories -
T1566.001 Spearphishing Attachment -
Used by Actors (1)
Metadata
ID: 122
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00