Sofacy is an APT28-associated Windows malware family name historically used for an early-stage implant also referred to as SOURFACE, and in some reporting linked alongside the CORESHELL naming lineage. It is part of the broader malware ecosystem used by the Russian state-linked espionage group widely tracked as APT28, Fancy Bear, Sednit, or STRONTIUM. The implant has been used in targeted cyber-espionage operations against government, military, defense, political, and security-related organizations, particularly in Europe and other regions aligned with Russian intelligence priorities.
As documented in public reporting on APT28 tradecraft, Sofacy/SOURFACE functioned as a first-stage foothold used to establish access and support follow-on deployment of more capable implants. Related APT28 tooling provided remote access and modular post-compromise functionality, and the Sofacy malware lineage is associated with encrypted and Base64-encoded command-and-control communications. CORESHELL-related variants in this lineage have been observed using custom stream ciphers for command traffic, establishing persistence through Windows autostart mechanisms, and being executed through rundll32 to proxy DLL execution. The malware family is therefore best understood as part of a staged espionage toolchain rather than a standalone commodity threat.
Operationally, Sofacy was commonly delivered in highly targeted spearphishing campaigns using themed lures and malicious attachments. Once access was established, APT28 frequently deployed additional backdoors and espionage modules to expand collection and maintain resilience. The malware family is closely associated with long-running Russian intelligence collection operations and is notable for its role in the early evolution of APT28’s intrusion toolkit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT28_2011-09_Telus_Trojan.Win32.Sofacy.A ... APT28_2015-07_Telus_Trojan-Downloader.Win32.Sofacy.B ... APT28_2015-12_Kaspersky_Sofacy APT hits high profile targets
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28_2011-09_Telus_Trojan.Win32.Sofacy.A ... APT28_2015-07_Telus_Trojan-Downloader.Win32.Sofacy.B ... APT28_2015-12_Kaspersky_Sofacy APT hits high profile targets | APT28_2014-10_Telus_Coreshell.A ... coreshell.dll
23 distinct techniques documented for this family, organized by ATT&CK tactic.
They also send emails purportedly containing links to news items, but instead linking to malware drop sites that install toolkits onto the target's computer.
"it uses zero-day exploits..." / "used a zero-day exploit of Java..." / "utilized 'two zero-day vulnerabilities in Adobe Flash and the down-level Windows kernel.'"
Among other things, it uses zero-day exploits, spear phishing and malware to compromise targets.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
SIMILAR e49bce75070a7a3c63a7cebb699342b3_CVE-2014-4076_tan.exe_
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
Together with the help of above mentioned tools, the group gained access to the file system and registry...
Together with the help of above mentioned tools, the group gained access to the file system and registry; enumerate network resources...
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
152 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware family associated with APT28 espionage operations.
... CORESHELL ... (v2.1→v2.2) ...
CORESHELL (v2.1→v2.2)
Malware that persists through ASEP Registry entries and shortcuts in the Quick Start folder.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.