X-Tunnel is a custom encrypted network proxy and pivoting tool associated with APT28, also tracked as Fancy Bear, Sednit, and Sofacy. It has been documented in the group’s long-running espionage operations since at least 2013 and was used during notable intrusions including the German Bundestag compromise and the 2016 Democratic National Committee intrusion. Within the broader APT28 toolchain, X-Tunnel has commonly operated alongside implants such as X-Agent and other post-compromise tooling to support internal network access and data theft.
The malware relays arbitrary network traffic between an external command-and-control server and a compromised endpoint inside a target network, effectively turning the infected host into a pivot point for access to internal systems. It supports multiple simultaneous tunnels and was enhanced over time with features including TLS-protected communications, HTTP proxy support, persistent HTTP connections, and fallback connectivity behavior in which the command-and-control server can provide an alternate port if the active connection is interrupted. Reporting also indicates that X-Tunnel traffic has used SSL/TLS and RC4-based encryption in some variants.
Beyond tunneling, X-Tunnel has been reported as capable of probing networks for open ports and accessing locally stored passwords on victim systems, indicating utility for internal reconnaissance and credential access during post-compromise operations. Its role in APT28 intrusions has been closely tied to stealthy lateral access, network pivoting, and exfiltration support rather than initial compromise. The malware is part of a mature, bespoke espionage ecosystem developed for targeted operations against government, political, military, diplomatic, and other high-value organizations, particularly those aligned with APT28’s longstanding geopolitical targeting priorities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2026-03-10 ⋅ ESET Research ⋅ Sednit reloaded: Back in the trenches BEARDSHELL GRUNT SLIMAGENT X-Agent XTunnel
23 distinct techniques documented for this family, organized by ATT&CK tactic.
They also send emails purportedly containing links to news items, but instead linking to malware drop sites that install toolkits onto the target's computer.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The source code contains two different channel implementations, one over HTTP and one over email... HttpChannel::getRawPacket() method is implemented as a HTTP GET request... sendRawPacket() is an HTTP POST request.
APT28_2016-07_Invincea_Tunnel of Gov DNC Hack and the Russian XTunnel ... PortMapClient.exe ... VmUpgradeHelper.exe ... APT28_2016-10_ESET_Observing the Comings and Goings Xtunnel
Xtunnel is a network proxy tool that can relay any kind of network traffic between a C&C server on the Internet and an endpoint computer inside a local network... An Xtunnel infected machine serves as a network pivot
Xtunnel first tries to retrieve the Internet Explorer proxy configuration... Once a proxy IP address has been chosen, Xtunnel uses the HTTP CONNECT method to reach its C&C server.
The Sednit group developed a network proxy tool, named Xtunnel, to effectively transform a compromised computer into a network pivot, in order to contact machines that are normally unreachable from the Internet... An Xtunnel infected machine serves as a network pivot to contact machines that are normally unreachable from the Internet.
The attackers then upgraded valuable targets to the X-Agent backdoor, often pairing it with the Sedreco loader and the X-Tunnel network pivot.
Xtunnel proxies network traffic between a C&C server on the Internet and a target computer, hence creating a “tunnel” between the two... UDP traffic tunneling was introduced
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2"). | Examples include: "encrypt C2 messages with AES-256-CBC sent underneath TLS", "encrypts C2 traffic with AES and RSA", "uses SSL/TLS and RC4", and "BlowFish algorithm".
On April 28, they used additional malware known as X-Tunnel to create an encrypted connection between the DCCC computers and GRU-controlled proxy computers for secure, large-scale data transfers, and then exfiltrated the over-70 Gigabytes of compressed data to a remote, GRU-controlled server.
56 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28/Sednit tunneling and backdoor utility used in espionage operations.
Tunneling/backdoor malware used by APT28 in expanded espionage operations.
Previously observed APT28 malware referenced here because it used the same opaque predicate obfuscation technique later seen in BEARDSHELL.
An APT28 network pivot and exfiltration tool commonly paired with X-Agent in major espionage operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.