Sofacy (APT28) targeted a U.S. government agency with a spear-phishing campaign that delivered a weaponized RTF document themed around the NATO exercise Noble Partner 2016. The attachment exploited CVE-2015-1641 to install a loader DLL and a Carberp-based Sofacy payload, then established persistence through an unusual Microsoft Office registry path under Software\Microsoft\Office test\Special\Perf, causing the malware to load whenever a user opened an Office application. The malware profiled infected hosts and used encrypted, Base64-encoded HTTP POST traffic to communicate with infrastructure including 191.101.31.6, while also beaconing to google.com.
The intrusion reflects a broader pattern highlighted by U.S. government agencies, which warned that foreign state-linked actors routinely exploit well-known vulnerabilities in Microsoft Office and other widely deployed products to gain initial access and sustain intrusions. CISA and the FBI have identified Office-related flaws among the most frequently abused weaknesses, alongside other long-lived vulnerabilities that remain effective because organizations delay patching or continue using outdated software. The case underscores the operational value of rapid patching, retiring end-of-life systems, and hardening Office and related enterprise software against phishing-led exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The U.S. government alert said sophisticated foreign cyber actors in 2020 were increasingly exploiting unpatched VPN vulnerabilities, including Citrix CVE-2019-19781 and Pulse Secure CVE-2019-11510. It also warned that attackers were taking advantage of rushed Office 365 deployments and broader organizational weaknesses.
The CISA alert said Chinese state cyber actors were still frequently exploiting CVE-2012-0158 as of December 2019. The flaw was one of the most commonly used vulnerabilities across multiple state-sponsored actors.
On May 28, 2016, the Sofacy/APT28 group sent a spear-phishing email to a U.S. government entity using a Noble Partner 2016-themed RTF attachment. The attachment attempted to exploit CVE-2015-1641 to install a loader DLL and a Carberp-based Sofacy payload.
CISA, the FBI, and the broader U.S. Government issued a joint alert identifying the top 10 vulnerabilities most exploited from 2016 through 2019 and urging organizations to prioritize patching. The alert highlighted Microsoft OLE-related flaws as especially common and tied frequent exploitation to actors linked to China, Iran, North Korea, and Russia.
Unit 42 published analysis of the Sofacy campaign, linking it to prior activity through overlapping infrastructure and a shared persistence artifact. The report also documented a previously unobserved Office-triggered registry persistence method under Software\Microsoft\Office test\Special\Perf.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
us-cert.cisa.gov
Open sourceresearchcenter.paloaltonetworks.com
Open sourcecve.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.