DealersChoice is a malicious-document framework/platform used by the Sednit threat group, also known as APT28, Fancy Bear, Sofacy, and Strontium. It is designed to generate malicious documents with embedded Adobe Flash Player exploits and leverages vulnerable versions of Flash to achieve code execution on victim systems. Reporting cited in the content describes two variants: a standalone form containing exploit code and payload, and a modular form that loads exploit code or payload on demand from command-and-control infrastructure. DealersChoice has been observed using HTTP for communication with its C2 server. The platform was used intensively by Sednit in late 2016, remained in use afterward, and was later observed again in 2017 and in updated form against embassies and EU agencies. Email attachments are described as a main entry point into the Sednit ecosystem, and DealersChoice was specifically associated with targeted phishing campaigns against ministries of foreign affairs, embassies, political parties, and other government-related entities. The content also notes that DealersChoice makes modifications to open-source scripts from GitHub and executes them on the victim’s machine.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
DealersChoice has previously been used to exploit a variety of Flash vulnerabilities, including CVE-2015-7645, CVE-2016-1019, CVE-2016-4117, and CVE-2016-7855 via embedded objects in crafted Microsoft Word documents.
DealersChoice has previously been used to exploit a variety of Flash vulnerabilities, including CVE-2015-7645, CVE-2016-1019, CVE-2016-4117, and CVE-2016-7855 via embedded objects in crafted Microsoft Word documents.
DealersChoice has previously been used to exploit a variety of Flash vulnerabilities, including CVE-2015-7645, CVE-2016-1019, CVE-2016-4117, and CVE-2016-7855 via embedded objects in crafted Microsoft Word documents.
DealersChoice has previously been used to exploit a variety of Flash vulnerabilities, including CVE-2015-7645, CVE-2016-1019, CVE-2016-4117, and CVE-2016-7855 via embedded objects in crafted Microsoft Word documents.
"...a new platform used by Sednit... which they called DealersChoice, has the ability to generate malicious documents with embedded Adobe Flash Player exploits."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...a new platform used by Sednit... which they called DealersChoice, has the ability to generate malicious documents with embedded Adobe Flash Player exploits."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sednit leveraged vulnerabilities… mostly Adobe Flash and Internet Explorer.” / “DealersChoice… embedded Adobe Flash Player exploits… selects one of three different vulnerabilities.”
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sofacy-associated exploitation/delivery framework used in targeted operations against diplomatic/government entities.
Sednit/APT28 tooling used in email-attachment-based intrusion chains (commonly referenced as an exploit framework for weaponized documents).
Malware/implant delivered via exploitation of vulnerable Adobe Flash versions to achieve code execution.
Malware that uses HTTP to communicate with its C2 server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.