X-Agent, also known as CHOPSTICK and SPLM, is a modular espionage backdoor associated with APT28, the Russian state-linked threat group also tracked as Sofacy or Sednit. It has been used as a selective second-stage implant in targeted intrusions against government, diplomatic, defense, political, and other high-value organizations worldwide. Reporting over time has tied the malware family to Windows, macOS, and Linux variants, reflecting a mature cross-platform capability within the APT28 toolset.
The malware supports remote command execution and interactive post-compromise control, enabling operators to run commands and manage infected systems. Documented surveillance functions include keylogging and screenshot capture. X-Agent also performs security software discovery by checking for antivirus and forensic tools, which supports operator awareness and defense evasion. Some variants store RC4-encrypted configuration data locally, including in the Windows Registry, and encrypt command-and-control traffic with RC4.
X-Agent has demonstrated resilient command-and-control behavior. Documented samples can switch to alternate command-and-control channels if the primary channel fails, and some variants use a domain generation algorithm as a fallback mechanism by constructing domains from word lists. On Windows, APT28 has executed X-Agent or CHOPSTICK components through rundll32, consistent with signed binary proxy execution for stealth and operational flexibility.
macOS reporting describes a modular backdoor architecture with reconnaissance, remote shell execution, screenshot capture, keylogging, file operations, password theft from Firefox, exfiltration, and discovery of iOS backups stored on Macs. Linux-related reporting in the APT28 ecosystem also links infrastructure and tooling overlaps between CHOPSTICK/X-Agent and Sofacy Linux malware operations. Overall, X-Agent is best characterized as a long-running, multi-platform espionage backdoor central to APT28 intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2015-12-17 ⋅ Bitdefender ⋅ APT28 Under the Scope: A Journey into Exfiltrating Intelligence and Government Information X-Agent XP PrivEsc (CVE-2014-4076)
IoCs Table 2 lists a lure document (World War3.docx; SHA-1 7aada8bcc0d1ab8ffb1f0fae4757789c6f5546a3) detected as SWF/Exploit.CVE-2017-11292.A; the report notes DealersChoice generates malicious documents with embedded Adobe Flash Player exploits.
IoCs Table 2 lists a phishing document (f3805382ae2e23ff1147301d131a06e00e4ff75f) detected as Win32/Exploit.CVE-2016-4117.A; the report describes Sednit’s DealersChoice platform embedding Adobe Flash Player exploits in malicious Office documents.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
Another unit mate, Capt. Nikolay Kozachek, allegedly crafted the X-Agent malware used to hack the Democratic Congressional Campaign Committee and DNC networks in April 2016.
...their involvement in the development of Unit 26165’s X-Agent malware
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple entries describe APT28/Pawn Storm/Sofacy campaigns using lure documents, themed emails, and phishing schemes, e.g., “APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme”, “New Spear Phishing Campaign Pretends to be EFF”, and “distribution of emails with 'instructions' on 'updating the operating system'”.
The malware uses a token to identify which module is communicating. The token is Base64 encoded data, but padded with a 5-byte random prefix so that it looks like valid Base64 data.
The Komplex Trojan is a binder with multiple parts: a dropper, a payload and a decoy pdf file.
One listed item explicitly names “T1055 Process Injection” and includes APT28-linked malware such as Downdelph among examples.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
InfoOS: Gather information from the infected computer, such as: IOPlatformUUID, process list, operating system version.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
RemoteShell: Used to execute remote commands received from the attacker on the infected machine. It lists installed applications as well as iPhone backups.
This backdoor component is known to have a modular structure featuring various espionage functionalities, such as key-logging, screen grabbing and file exfiltration.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
The command request to the C&C server is made via HTTP GET. It receives a base64 encoded cmdPacket that has previously been encrypted with RC4 using a hardcoded KERNEL_CRYPTO_MAIN_KEY.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
C2 azureon-line[.]com (TCP/80) ... C2 198.105.125[.]74 (TCP/80) ... C2 mozilla-plugins[.]com (TCP/80) ... The oldest sample... was found to beacon to the domain azureon-line[.]com... The first of the newer samples... beacons to an IP also widely associated with the Sofacy group... The newest sample... introduces a previously unknown command and control beacon to mozilla-plugins[.]com.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Recommended yara for the linux versions: rule sofacy_xagent ... x4 = "ChannelController" x5 = "RemoteKeylogger"
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
110 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-running APT28/Sednit espionage backdoor family with Windows, macOS, Linux, Android, and iOS variants referenced across the content.
Malware used by APT28 as part of expanded espionage operations.
A custom-built remote access trojan used to establish access, monitor victim networks, execute commands remotely, and transfer files to and from command-and-control servers.
APT28’s long-running signature implant, referenced here as the code ancestor of Slimagent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.