ADVSTORESHELL, also known as AZZY and associated with the Sednit/Sofacy/APT28 intrusion set, is a Windows espionage backdoor used in targeted operations against high-value organizations, including government, political, and aerospace-related entities. It has been documented as a core second-stage implant in multi-component APT28 intrusion chains, where it is installed by earlier-stage droppers and configured to contact attacker-controlled command-and-control infrastructure using embedded configuration data.
The malware provides broad remote administration and collection functionality. Documented capabilities include listing running processes, enumerating Registry keys, modifying and deleting Registry values, listing connected devices, launching processes via native Windows APIs, deleting files and directories, keylogging, and exfiltrating collected data over its command-and-control channel. It stores command execution output locally before transmission and supports persistent access by registering itself for execution at user logon through a Windows Run key.
ADVSTORESHELL communications are protected through encrypted command-and-control traffic that is subsequently Base64-encoded; some variants additionally use 3DES for portions of network traffic. Reporting has also described configurations and related deployments using stronger cryptographic protection in parts of the broader intrusion workflow. The malware has been linked to long-running Russian state-aligned cyber-espionage activity attributed to APT28, also tracked as Sednit, Sofacy, and Fancy Bear. Within that ecosystem, ADVSTORESHELL has appeared alongside other implants and tooling such as Sedreco, X-Agent, X-Tunnel, credential-dumping utilities, and bespoke exfiltration modules.
ADVSTORESHELL is best characterized as a full-featured espionage backdoor for Windows environments, designed for durable access, host reconnaissance, surveillance, and theft of victim data during targeted post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28_2016-10_ESET_Observing the Comings and Goings Sedreco-dropper ... Sedreco_payload | APT28_2015-12_Kaspersky_Sofacy APT hits high profile targets ... AZZYimplants-USBStealer ... Stand-aloneAZZYbackdoor
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Together with the help of above mentioned tools, the group gained access to the file system and registry; enumerate network resources; create processes... | It used a downloader tool that FireEye dubbed " SOURFACE ", a backdoor labelled " EVILTOSS " that gives hackers remote access and a flexible modular implant called " CHOPSTICK " to enhance functionality of the espionage software.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information. | Multiple entries explicitly state use of the Windows systeminfo command, e.g., 'BlackEnergy has used Systeminfo to gather the OS version...' and 'OilRig has run hostname and systeminfo on a victim.'
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
The attackers then upgraded valuable targets to the X-Agent backdoor, often pairing it with the Sedreco loader and the X-Tunnel network pivot.
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
76 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor/tool in the Sofacy/APT28 espionage toolset used against high-profile targets.
A loader used alongside X-Agent and X-Tunnel in APT28's historical espionage toolkit.
A backdoor historically used by APT28 for cyber-espionage operations.
A Sednit full-fledged espionage backdoor mentioned as part of the group’s historical custom implant arsenal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.