SoreFang is a Windows malware family associated with APT29, the Russian SVR-linked espionage group. It has been described as a first-stage downloader used in targeted intrusions, including operations against organizations involved in COVID-19 vaccine research and development. The malware is used to establish an initial foothold, profile compromised hosts, and support delivery of additional payloads for follow-on espionage activity.
Observed functionality includes persistence through Windows Scheduled Tasks, local and domain account discovery using native Windows net commands, domain group enumeration, process discovery using Tasklist, and local network configuration discovery using ipconfig. SoreFang can collect usernames from the local system, enumerate domain accounts and groups, and gather TCP/IP, DNS, DHCP, and network adapter configuration from infected hosts. It also includes functionality to decode and decrypt data associated with command-and-control communications and exfiltration workflows.
SoreFang has been linked to exploitation of a Sangfor SSL VPN vulnerability to place and deliver malicious update binaries, indicating its use both as a staged payload and as part of intrusion chains leveraging public-facing infrastructure. Its tradecraft is consistent with APT29 operations focused on stealthy access, host reconnaissance, persistence, and deployment of additional malware within high-value victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Multiple tools/actors are described using Active Directory/domain group enumeration, e.g., “AdFind can enumerate domain groups”, “net group "domain admins" /domain to enumerate domain groups”, “BloodHound can collect information about domain groups and members”, and “AD Explorer tool to enumerate groups on a victim's network.”
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Known Malware: APT29 GeminiDuke - A malware that collects information on local user accounts from the victim...
AdFind can enumerate domain users. APT41 used built-in net commands to enumerate domain administrator users. BloodHound can collect information about domain users, including identification of domain admin accounts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... SoreFang ... (v1.0→v1.1) ...
SoreFang (v1.0→v1.1)
Their toolkit includes ... Sibot, SoreFang, SUNBURST, SUNSPOT...
Custom malware attributed to SVR, referenced in the context of targeting COVID-19 vaccine development organizations; also stated to have been used against energy sector companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.