APT28, also tracked as Sofacy, Fancy Bear, Sednit, and Strontium, conducted sustained cyber-espionage operations against political, government, telecommunications, aerospace, and Ukraine-linked targets using spear phishing, typosquatted sites, exploit delivery, and custom malware. Reporting tied the group to campaigns that deployed first-stage downloaders, backdoors, credential-dumping tools, exfiltration modules, and the Seduploader malware family, including a macro-enabled Word lure themed around a cybersecurity conference that executed rundll32.exe to install persistence and enable screenshot capture, file download, code execution, and data theft. Separate analysis also documented Fysbis, a Linux backdoor linked to Sofacy infrastructure, showing the group’s cross-platform capability and continued use of modular implants for covert access.
Defenders and platform operators responded with both technical guidance and infrastructure disruption. The UK’s NCSC published indicators of compromise and detection guidance for APT28 malware including X-Tunnel, X-Agent, and CompuTrace, while Microsoft said it obtained a court order to seize seven domains used by the group and redirect them to a sinkhole after the infrastructure was used to target Ukrainian institutions as well as U.S. and EU government and think-tank networks for persistent access and exfiltration. Across the referenced reporting, APT28’s operations were characterized by curated targeting, evolving malware variants, and repeated use of attacker-controlled domains and command-and-control systems to support intelligence collection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2018-10-04, the UK's NCSC published an alert providing indicators of compromise, signatures, and mitigation guidance for malware and tooling used by APT28.
On 2016-02-12, Palo Alto Networks Unit 42 published technical analysis of the Fysbis Linux backdoor, linking multiple samples and infrastructure elements to Sofacy/APT28.
On February 16, 2015, APT28 launched a second scanning campaign against 58,624 IPs, primarily in Spain, and identified 6,146 as vulnerable.
On February 14, 2015, the attackers saved a database backup to file.csv and then moved their scanning focus away from Ukraine toward Spain.
Between February 10 and February 14, 2015, APT28 scanned millions of Ukrainian IP addresses for vulnerabilities, with Bitdefender linking the activity to the Minsk ceasefire summit period.
Unit 42 analyzed a late-2015 64-bit Fysbis sample that used mozilla-plugins[.]com for command and control and a rolling double-XOR algorithm to decode installation and C2 data.
Unit 42 documented an early-2015 32-bit Fysbis sample that persisted as ksysdefd and communicated with 198.105.125[.]74 over TCP/80.
Unit 42 analyzed a late-2014 64-bit Fysbis sample attributed to Sofacy that installed as /bin/rsyncd or ~/.config/dbus-notifier/dbus-inotifier and used azureon-line[.]com for command and control.
Trend Micro published a 2014 reference on Operation Pawn Storm that linked APT28 to the use of Sedreco and Seduploader in targeted operations. This adds an earlier documented malware campaign in the group's tooling history.
Bitdefender's analysis describes APT28/Sofacy as a long-running advanced persistent threat that had been active in Europe since 2007.
Microsoft disclosed that it obtained a court order to take control of seven domains used by APT28, redirecting them to a sinkhole to disrupt attacks against Ukrainian institutions and other targets in the US and EU.
Cisco Talos discovered a campaign using a weaponized Word document named Conference_on_Cyber_Conflict.doc to drop a new Seduploader variant via malicious VBA macros.
Talos reported that metadata showed the attackers created the malicious Office documents and PE files used in the Cyber Conflict-themed campaign on Wednesday, October 4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcethehackernews.com
Open sourcencsc.gov.uk
Open sourceblog.talosintelligence.com
Open sourceunit42.paloaltonetworks.com
Open sourcedownload.bitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.