X-Agent, also known as CHOPSTICK and SPLM, is a modular espionage implant associated with APT28, the Russia-linked threat group also tracked as Fancy Bear, Sofacy, and Sednit. It has been used for long-term intelligence collection against government, military, diplomatic, political, and related high-value targets, including operations tied to Ukraine and other NATO-aligned interests.
The malware functions as a remote access trojan and backdoor that gives operators persistent interactive access to compromised Windows systems. Reported capabilities include remote command execution, file transfer, keylogging, screenshot collection, access to the Windows Registry, network activity monitoring, and information gathering from the victim environment. X-Agent has also been used alongside companion tooling such as X-Tunnel for data exfiltration and network pivoting.
CHOPSTICK/X-Agent incorporates defensive awareness and anti-analysis features. It can check for antivirus and forensic tooling, perform runtime checks to identify analysis environments, and alter or prevent execution when such conditions are detected. It also uses encrypted command-and-control communications, including TLS, and has been observed using HTTP and HTTPS as transport channels depending on module configuration. Some variants store RC4-encrypted configuration data in the Windows Registry.
Delivery has historically been closely tied to APT28 intrusion tradecraft, especially spearphishing operations using themed lures and malicious attachments. The malware has also appeared within broader APT28 toolchains that included downloaders and other implants to establish access and extend espionage functionality.
X-Agent is one of APT28’s best-known signature implants of the 2010s and has shown continuity into later tooling. More recent malware such as SlimAgent has been assessed as deriving from X-Agent’s keylogging component, underscoring the family’s long-term role in APT28’s custom malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
IoCs Table 2 lists a lure document (World War3.docx; SHA-1 7aada8bcc0d1ab8ffb1f0fae4757789c6f5546a3) detected as SWF/Exploit.CVE-2017-11292.A; the report notes DealersChoice generates malicious documents with embedded Adobe Flash Player exploits.
IoCs Table 2 lists a phishing document (f3805382ae2e23ff1147301d131a06e00e4ff75f) detected as Win32/Exploit.CVE-2016-4117.A; the report describes Sednit’s DealersChoice platform embedding Adobe Flash Player exploits in malicious Office documents.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 evolved PixyNetLoader, utilizing COM persistence, PNG steganography, and FILEN-based cloud C2, and expanded its tactics to include X-Agent, X-Tunnel, and LameHug.
Another unit mate, Capt. Nikolay Kozachek, allegedly crafted the X-Agent malware used to hack the Democratic Congressional Campaign Committee and DNC networks in April 2016.
...their involvement in the development of Unit 26165’s X-Agent malware
...their involvement in the development of Unit 26165’s X-Agent malware
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Together with the help of above mentioned tools, the group gained access to the file system and registry; enumerate network resources; create processes... | It used a downloader tool that FireEye dubbed " SOURFACE ", a backdoor labelled " EVILTOSS " that gives hackers remote access and a flexible modular implant called " CHOPSTICK " to enhance functionality of the espionage software.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The threat group implements counter-analysis techniques to obfuscate their code. They add junk data to encoded strings, making decoding difficult without the junk removal algorithm.
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads. Operation Spalax threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Consistent with GRU techniques and 'methods of persistence' identified by computer forensic investigators in other intrusions, the hackers again used X-Agent to log keystrokes, take screenshots, and gather system data; used a lateral-movement tool called RemCom; and used Mimikatz, a credential-harvesting tool.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Together with the help of above mentioned tools, the group gained access to the file system and registry; enumerate network resources...
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
CHOPSTICK includes runtime checks to identify an analysis environment and prevent execution on it. Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads. Operation Spalax threat actors used droppers that would run anti-analysis checks before executing malware on a compromised host.
These actors set up operational infrastructure to obfuscate their source infrastructure, host domains and malware for targeting organizations, establish command and control nodes, and harvest credentials and other valuable information from their targets.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
The Xagent backdoor can communicate with its C&C server over email with a custom protocol... MailChannel... SMTP to send emails and POP3 to receive emails (over TLS)
APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims.
APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims.
The Xagent backdoor can communicate with its C&C server over email with a custom protocol... messages are sent and received as attachments to emails... Sedreco core threads store the output generated by a command execution in the outbound file... periodically transmitted in bulk to the server.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
86 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by APT28 as part of expanded espionage operations.
A custom-built remote access trojan used to establish access, monitor victim networks, execute commands remotely, and transfer files to and from command-and-control servers.
APT28’s long-running signature implant, referenced here as the code ancestor of Slimagent.
APT28的标志性植入程序,与Slimagent存在直接代码渊源。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.