X-Agent, also known as CHOPSTICK and SPLM, is a modular espionage backdoor used by APT28, the Russian GRU-linked threat actor also known as Sofacy, Sednit, and Fancy Bear. It is deployed selectively as a second-stage implant against targets worldwide. The family includes Windows, Linux, iOS, and macOS variants and supports remote command execution, keylogging, and screenshot collection.
Its command-and-control mechanisms include HTTP, HTTPS, and other channels selected according to module configuration. CHOPSTICK encrypts communications with RC4, can switch channels when an existing connection fails, and can generate fallback domains by concatenating words from predefined lists. It also checks for antivirus and forensic software. APT28 has executed Windows DLL variants through the legitimate Rundll32 utility.
The macOS variant provides system and process reconnaissance, remote shell execution, file manipulation and execution, Firefox password theft, screenshot capture, keylogging, and file exfiltration through HTTP and FTP. It can discover and steal iOS backups stored on compromised Macs. Its communications use RC4 encryption and Base64 encoding, and it performs anti-debugging checks. Capabilities vary by platform and module configuration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2015-12-17 ⋅ Bitdefender ⋅ APT28 Under the Scope: A Journey into Exfiltrating Intelligence and Government Information X-Agent XP PrivEsc (CVE-2014-4076)
IoCs Table 2 lists a lure document (World War3.docx; SHA-1 7aada8bcc0d1ab8ffb1f0fae4757789c6f5546a3) detected as SWF/Exploit.CVE-2017-11292.A; the report notes DealersChoice generates malicious documents with embedded Adobe Flash Player exploits.
IoCs Table 2 lists a phishing document (f3805382ae2e23ff1147301d131a06e00e4ff75f) detected as Win32/Exploit.CVE-2016-4117.A; the report describes Sednit’s DealersChoice platform embedding Adobe Flash Player exploits in malicious Office documents.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Later implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.
Another unit mate, Capt. Nikolay Kozachek, allegedly crafted the X-Agent malware used to hack the Democratic Congressional Campaign Committee and DNC networks in April 2016.
...their involvement in the development of Unit 26165’s X-Agent malware
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple entries describe APT28/Pawn Storm/Sofacy campaigns using lure documents, themed emails, and phishing schemes, e.g., “APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme”, “New Spear Phishing Campaign Pretends to be EFF”, and “distribution of emails with 'instructions' on 'updating the operating system'”.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains.
77 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
112 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Long-running APT28/Sednit espionage backdoor family with Windows, macOS, Linux, Android, and iOS variants referenced across the content.
Malware used by APT28 as part of expanded espionage operations.
A custom-built remote access trojan used to establish access, monitor victim networks, execute commands remotely, and transfer files to and from command-and-control servers.
APT28’s long-running signature implant, referenced here as the code ancestor of Slimagent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.