APT28__2015__Operation_RussianDoll.pdf
ID: 061437d1-b765-44a9-add4-7b6fd58c4a8e
STIX ID: report--061437d1-b765-44a9-add4-7b6fd58c4a8e
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes "Operation RussianDoll," a highly targeted APT28 campaign observed beginning April 13, 2015 that chained an Adobe Flash zero-day (CVE-2015-3043) with a Windows local privilege escalation (CVE-2015-1701) to gain remote code execution and SYSTEM privileges; the report includes low-level exploit analysis, shellcode/payload behavior, C2/infrastructure mappings (several IPs/domains in 87.236.215.0/24), and links the malware to APT28 families CHOPSTICK and CORESHELL.
