DownRage is referenced in the provided content as a dropper associated with Sofacy/APT28 (Fancy Bear). The only direct technical context given is a mention listing “Sofacy, X-Agent, X-Tunnel, WinIDS, Foozer and DownRage droppers.” Based on the content, DownRage is malware used as a dropper within the Sofacy/APT28 toolset. The broader incident context ties this toolset to Russian intelligence-affiliated intrusion activity, including the 2016 Democratic National Committee compromise attributed by CrowdStrike to FANCY BEAR/APT28 and COZY BEAR/APT29. However, the provided content does not supply specific details on DownRage’s functionality, infection vector, persistence, command-and-control, targeted industries or systems, or indicators of compromise. No hashes, filenames, domains, IPs, or other DownRage-specific IOCs are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a dropper in the FANCY BEAR/APT28 toolset.
Dropper attributed to the FANCY BEAR toolset; specific behavior not detailed in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.