Cannon is a Windows trojan associated with APT28, also known as Sofacy or Fancy Bear, and is linked to the Zebrocy malware ecosystem used in cyber-espionage operations. Public reporting in 2018 identified Cannon as a successor or evolution within that toolset, used in targeted intrusions against government and related organizations.
Cannon supports host reconnaissance and collection functions including gathering the current username, enumerating running processes, collecting the victim system’s time zone information, and capturing screenshots of the desktop. It also exfiltrates collected information through an email-based command-and-control architecture using SMTP/S and POP3/S, an uncommon but well-documented transport choice that blends command-and-control and data theft into the same channel.
The malware’s observed behavior is consistent with post-compromise surveillance and victim profiling rather than destructive activity. Its capabilities support operator awareness of the victim environment and collection of potentially sensitive on-screen information. Cannon is best understood as an espionage-oriented implant within the broader APT28/Sofacy intrusion toolkit.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2018-11-20 ⋅ Palo Alto Networks Unit 42 ⋅ Sofacy Continues Global Attacks and Wheels Out New ‘Cannon’ Trojan
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple entries describe APT28/Pawn Storm/Sofacy campaigns using lure documents, themed emails, and phishing schemes, e.g., “APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme”, “New Spear Phishing Campaign Pretends to be EFF”, and “distribution of emails with 'instructions' on 'updating the operating system'”.
Examples include “PowerPoint mouse-over event abused to deliver Graphite implants”, “BREXIT-themed lure document that delivers ZEKAPAB malware”, “fake NATO training docs to breach govt networks”, and repeated references to lure documents delivering Zebrocy or Seduploader.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sofacy/APT28 trojan/backdoor used in global attacks.
Malware that gathers the username from the system.
Malware that exfiltrates collected data over email-based C2 channels.
Gathers the username from the system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.