logo

APT28__2016__PaloAlto_A-Look-Into-Fysbis-Sofacys-Linux-Backdoor_Feb-12-16.pdf

ID: 0802b454-df67-499b-bd6c-951ccdbcd65e

STIX ID: report--0802b454-df67-499b-bd6c-951ccdbcd65e

Threat Score

75/100

Uploaded: 2026-08-07

Published Date: 2016-04-04

Last Modified Date: 2016-04-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 blog report analyzes the Fysbis Linux backdoor used by the Sofacy (APT28) actor: it describes multiple 32-/64-bit ELF samples, installation/persistence behaviors, capabilities (remote shell, keylogger), C2 domains and IPs (e.g., azureon-line.com, 198.105.125.74, mozilla-plugins.com), and provides IOCs and detection guidance for defenders.