logo

APT28__2015__Operation_RussianDoll.pdf

ID: 061437d1-b765-44a9-add4-7b6fd58c4a8e

STIX ID: report--061437d1-b765-44a9-add4-7b6fd58c4a8e

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes "Operation RussianDoll," a highly targeted APT28 campaign observed beginning April 13, 2015 that chained an Adobe Flash zero-day (CVE-2015-3043) with a Windows local privilege escalation (CVE-2015-1701) to gain remote code execution and SYSTEM privileges; the report includes low-level exploit analysis, shellcode/payload behavior, C2/infrastructure mappings (several IPs/domains in 87.236.215.0/24), and links the malware to APT28 families CHOPSTICK and CORESHELL.