Foozer is a malware implant associated with Fancy Bear, also known as APT28, Sofacy, Sednit, STRONTIUM, and Pawn Storm. In the provided content, Foozer is listed among the implants and droppers used by Fancy Bear alongside WinIDS, X-Agent, X-Tunnel, Sofacy, and DownRange/DownRage droppers. The broader reporting in the content characterizes Fancy Bear as a Russian state-sponsored cyber espionage group widely linked to the GRU, including GRU Unit 26165, and known for spearphishing, credential theft, malware deployment, and use of zero-day exploits against government, military, political, media, and international organization targets. However, the provided content does not include specific technical details on Foozer’s functionality, infection vector, persistence, command-and-control behavior, targeted platforms, or indicators of compromise such as hashes, domains, IPs, or file paths. High-confidence attribution from the content is limited to Foozer being one of the implants utilized by Fancy Bear/APT28.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Fancy Bear utilises a number of implants, including Foozer, WinIDS, X-Agent, X-Tunnel, Sofacy, and DownRange droppers.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a dropper in the FANCY BEAR/APT28 toolset.
Dropper attributed to the FANCY BEAR toolset; specific behavior not detailed in the provided content.
An implant used by Fancy Bear as part of its espionage malware suite.
APT28-associated implant referenced as part of the group’s modular implant set used for persistence and operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.