APT28__2016__PaloAlto_A-Look-Into-Fysbis-Sofacys-Linux-Backdoor_Feb-12-16.pdf
ID: 0802b454-df67-499b-bd6c-951ccdbcd65e
STIX ID: report--0802b454-df67-499b-bd6c-951ccdbcd65e
Threat Score
75/100
Uploaded: 2026-08-07
Published Date: 2016-04-04
Last Modified Date: 2016-04-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 blog report analyzes the Fysbis Linux backdoor used by the Sofacy (APT28) actor: it describes multiple 32-/64-bit ELF samples, installation/persistence behaviors, capabilities (remote shell, keylogger), C2 domains and IPs (e.g., azureon-line.com, 198.105.125.74, mozilla-plugins.com), and provides IOCs and detection guidance for defenders.
