X-Tunnel is a custom encrypted network proxy and pivoting tool associated with the Russian state-sponsored espionage group APT28, also known as Fancy Bear, Sednit, Sofacy, and GRU Unit 26165. It was a core component of APT28’s 2010s intrusion toolkit alongside X-Agent and Sedreco, and was used in high-profile espionage operations including intrusions involving the German Bundestag and the 2016 Democratic National Committee compromise. Its role in those operations was to relay traffic between attacker-controlled infrastructure and compromised systems inside victim networks, enabling covert exfiltration and internal network access through an infected host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 evolved PixyNetLoader, utilizing COM persistence, PNG steganography, and FILEN-based cloud C2, and expanded its tactics to include X-Agent, X-Tunnel, and LameHug.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
They also send emails purportedly containing links to news items, but instead linking to malware drop sites that install toolkits onto the target's computer.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine. Agent Tesla has the ability to extract credentials from configuration or support files. APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome.
CrowdStrike had prepared a technical report to go online later that morning. The security firm carefully outlined some of the allegedly “superb” tradecraft of both intrusions: the Russian software implants were stealthy, they could sense locally-installed virus scanners and other defenses, the tools were customizable through encrypted configuration files, they were persistent, and the intruders used an elaborate command-and-control infrastructure.
The source code contains two different channel implementations, one over HTTP and one over email... HttpChannel::getRawPacket() method is implemented as a HTTP GET request... sendRawPacket() is an HTTP POST request.
The Sednit group developed a network proxy tool, named Xtunnel, to effectively transform a compromised computer into a network pivot, in order to contact machines that are normally unreachable from the Internet
Xtunnel is a network proxy tool that can relay any kind of network traffic between a C&C server on the Internet and an endpoint computer inside a local network... An Xtunnel infected machine serves as a network pivot
Xtunnel first tries to retrieve the Internet Explorer proxy configuration... Once a proxy IP address has been chosen, Xtunnel uses the HTTP CONNECT method to reach its C&C server.
The Sednit group developed a network proxy tool, named Xtunnel, to effectively transform a compromised computer into a network pivot, in order to contact machines that are normally unreachable from the Internet... An Xtunnel infected machine serves as a network pivot to contact machines that are normally unreachable from the Internet.
The attackers then upgraded valuable targets to the X-Agent backdoor, often pairing it with the Sedreco loader and the X-Tunnel network pivot.
Xtunnel proxies network traffic between a C&C server on the Internet and a target computer, hence creating a “tunnel” between the two... UDP traffic tunneling was introduced
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2"). | Examples include: "encrypt C2 messages with AES-256-CBC sent underneath TLS", "encrypts C2 traffic with AES and RSA", "uses SSL/TLS and RC4", and "BlowFish algorithm".
On April 28, they used additional malware known as X-Tunnel to create an encrypted connection between the DCCC computers and GRU-controlled proxy computers for secure, large-scale data transfers, and then exfiltrated the over-70 Gigabytes of compressed data to a remote, GRU-controlled server.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tunneling/backdoor malware used by APT28 in expanded espionage operations.
Previously observed APT28 malware referenced here because it used the same opaque predicate obfuscation technique later seen in BEARDSHELL.
An APT28 network pivot and exfiltration tool commonly paired with X-Agent in major espionage operations.
A Sednit network-pivoting tool from the 2010s referenced for shared obfuscation techniques with BeardShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.