Sofacy is a malware family associated with the Russian state-linked threat actor APT28, also known as Fancy Bear, Sednit, and STRONTIUM. In the provided reporting, “Sofacy” also refers to the group’s early first-stage implant from 2011–2012, which FireEye dubbed SOURFACE. The content links Sofacy/APT28 to long-running cyber espionage operations targeting governments, militaries, defense contractors, NATO-aligned entities, security organizations, and Ukraine-related targets.
The malware ecosystem associated with Sofacy expanded over time. The content states that after the early Sofacy/SOURFACE implant, APT28 added CORESHELL, CHOPSTICK (also referred to as SPLM/XAgent in one source), JHUHUGIT, and AZZY. FireEye described SOURFACE as a downloader, EVILTOSS as a backdoor providing remote access, and CHOPSTICK as a modular implant used to extend espionage functionality. Once access was established, operators reportedly deployed additional backdoors, USB stealers, and tools such as Mimikatz for lateral movement.
Capabilities directly described in the content include remote access, access to victim file systems and registries, network resource enumeration, process creation, keylogging, access to stored credentials, shellcode execution, encrypted data exfiltration using an RSA public key, and collection from removable media via USB stealer modules. A 2015 campaign description notes Sofacy used multi-backdoor packages for resilience and rapidly recompiled and redeployed malware after detection.
Observed infection and execution methods include spear-phishing emails with themed lures and malicious attachments, fake domains tied to defense events, and exploitation of multiple zero-days in Microsoft Office, Java, Adobe Flash Player, and Windows. The content specifically mentions CVE-2015-2590 being used to deliver JHUHUGIT. CORESHELL is described as being installed via rundll32 with exports named "init" or "InitW," and APT28 is also noted as executing CHOPSTICK via rundll32.
Network and C2 behavior described in the content includes CORESHELL communications over HTTP, Base64-encoded C2 messages, and encryption with custom stream ciphers using six-byte or eight-byte keys. One AZZY 4.3-related helper DLL reportedly used WinINet, connected over port 80, used the user-agent string "MSIE 8.0," and sent HTTP POST requests to "/store/." Hardcoded infrastructure mentioned for AZZY-related components includes intelnetservice[.]com, intelsupport[.]net, drivres-update[.]info, and softupdates[.]info.
Persistence and host artifacts directly mentioned include installation of msdeltemp.dll under %LOCAL_APPDATA%\Microsoft\Windows or %TEMP%, creation of the Run key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\StartUpChekTemp to launch RUNDLL32.EXE against msdeltemp.dll, and USB stealer stash directories under %MYPICTURES%%volume serial number%. A USB stealer configuration file named NvCpld.dat is also mentioned.
Specific malware samples and artifacts cited in the content include AZZY sample MD5 a96f4b8ac7aa9dbf4624424b7602d4f7, replacement AZZY sample MD5 9d2f9e19db8c20dc0d20d50869c7a373, downloader msdeltemp.dll MD5 ce8b99df8642c065b6af43fde1f786a3, external helper DLL tf394kv.dll MD5 8c4d896957c36ec4abeb07b2802268b9, AZZY dropper MD5 c3ae4a37094ecfe95c2badecf40bf5bb, older downloader DLL MD5 f6f88caf49a3e32174387cacfa144a89, and USB stealer DLL MD5 8b238931a7f64fddcad3057a96855f6c.
Aliases directly supported by the content for this malware include CORESHELL and SOURFACE.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It used a downloader tool that FireEye dubbed "SOURFACE", a backdoor labelled "EVILTOSS" that gives hackers remote access and a flexible modular implant called "CHOPSTICK" to enhance functionality of the espionage software.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
They also send emails purportedly containing links to news items, but instead linking to malware drop sites that install toolkits onto the target's computer.
"it uses zero-day exploits..." / "used a zero-day exploit of Java..." / "utilized 'two zero-day vulnerabilities in Adobe Flash and the down-level Windows kernel.'"
Among other things, it uses zero-day exploits, spear phishing and malware to compromise targets.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Together with the help of above mentioned tools, the group gained access to the file system and registry...
Together with the help of above mentioned tools, the group gained access to the file system and registry; enumerate network resources...
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... CORESHELL ... (v2.1→v2.2) ...
CORESHELL (v2.1→v2.2)
Named as one of multiple implants in the FANCY BEAR/APT28 toolset in this report.
A malware/implant family name associated with the FANCY BEAR toolset used in targeted intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.