XTunnel, also known as X-Tunnel and XAPS, is a malicious network-tunneling and proxy tool associated with APT28, also tracked as Fancy Bear, Sednit, and Sofacy, a Russian cyberespionage group attributed to GRU Unit 26165. It relays arbitrary network traffic between an Internet-based command-and-control server and a compromised endpoint inside a local network, supporting post-compromise network pivoting and data exfiltration. It was used in the 2016 Democratic National Committee intrusion and has been linked through malware and infrastructure similarities to the German Bundestag compromise.
XTunnel can probe networks for open ports and access passwords stored locally on victim systems. It uses SSL/TLS and RC4 to encrypt traffic, with analyzed samples incorporating OpenSSL. Its command-and-control server can supply an alternate port to maintain connectivity if the active connection closes. The malware employs code obfuscation, including a distinctive opaque-predicate technique also found in APT28’s BeardShell implant. XTunnel forms part of APT28’s custom espionage toolkit alongside X-Agent; its primary operational role is traffic relay and exfiltration rather than X-Agent’s keylogging and screenshot collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The APT28 software table lists XTunnel with proxying, encrypted channels, fallback channels, network-service scanning, and obfuscation.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
They also send emails purportedly containing links to news items, but instead linking to malware drop sites that install toolkits onto the target's computer.
Opaque predicate obfuscation (T1027) в BEARDSHELL - техника, ранее замеченная в XTunnel этой же группы.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The source code contains two different channel implementations, one over HTTP and one over email... HttpChannel::getRawPacket() method is implemented as a HTTP GET request... sendRawPacket() is an HTTP POST request.
APT28_2016-07_Invincea_Tunnel of Gov DNC Hack and the Russian XTunnel ... PortMapClient.exe ... VmUpgradeHelper.exe ... APT28_2016-10_ESET_Observing the Comings and Goings Xtunnel
Xtunnel is a network proxy tool that can relay any kind of network traffic between a C&C server on the Internet and an endpoint computer inside a local network... An Xtunnel infected machine serves as a network pivot
Xtunnel first tries to retrieve the Internet Explorer proxy configuration... Once a proxy IP address has been chosen, Xtunnel uses the HTTP CONNECT method to reach its C&C server.
The attackers then upgraded valuable targets to the X-Agent backdoor, often pairing it with the Sedreco loader and the X-Tunnel network pivot.
Xtunnel proxies network traffic between a C&C server on the Internet and a target computer, hence creating a “tunnel” between the two... UDP traffic tunneling was introduced
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2"). | Examples include: "encrypt C2 messages with AES-256-CBC sent underneath TLS", "encrypts C2 traffic with AES and RSA", "uses SSL/TLS and RC4", and "BlowFish algorithm".
On April 28, they used additional malware known as X-Tunnel to create an encrypted connection between the DCCC computers and GRU-controlled proxy computers for secure, large-scale data transfers, and then exfiltrated the over-70 Gigabytes of compressed data to a remote, GRU-controlled server.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28/Sednit tunneling and backdoor utility used in espionage operations.
Tunneling/backdoor malware used by APT28 in expanded espionage operations.
Previously observed APT28 malware referenced here because it used the same opaque predicate obfuscation technique later seen in BEARDSHELL.
An APT28 network pivot and exfiltration tool commonly paired with X-Agent in major espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.