{
  "type": "malware",
  "spec_version": "2.1",
  "id": "malware--959f3b19-2dc8-48d5-8942-c66813a5101a",
  "created": "2020-09-29T17:48:27.517Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/software/S0515",
      "external_id": "S0515"
    },
    {
      "source_name": "CISA WellMail July 2020",
      "description": "CISA. (2020, July 16). MAR-10296782-3.v1 – WELLMAIL. Retrieved September 29, 2020.",
      "url": "https://us-cert.cisa.gov/ncas/analysis-reports/ar20-198c"
    },
    {
      "source_name": "NCSC APT29 July 2020",
      "description": "National Cyber Security Centre. (2020, July 16). Advisory: APT29 targets COVID-19 vaccine development. Retrieved September 29, 2020.",
      "url": "https://www.ncsc.gov.uk/files/Advisory-APT29-targets-COVID-19-vaccine-development-V1-1.pdf"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "modified": "2025-04-25T14:44:06.771Z",
  "name": "WellMail",
  "description": "[WellMail](https://attack.mitre.org/software/S0515) is a lightweight malware written in Golang used by [APT29](https://attack.mitre.org/groups/G0016), similar in design and structure to [WellMess](https://attack.mitre.org/software/S0514).(Citation: CISA WellMail July 2020)(Citation: NCSC APT29 July 2020)",
  "is_family": true,
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_platforms": [
    "Windows"
  ],
  "x_mitre_deprecated": false,
  "x_mitre_domains": [
    "enterprise-attack"
  ],
  "x_mitre_version": "1.0",
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_contributors": [
    "Josh Campbell, Cyborg Security, @cyb0rgsecur1ty"
  ],
  "x_mitre_aliases": [
    "WellMail"
  ]
}