APT28__2015__Microsoft_Security_Intelligence_Report_Volume_19_English_11-16-2015.pdf
ID: 20ab634c-e594-4dc2-8e3f-d0894a5b0222
STIX ID: report--20ab634c-e594-4dc2-8e3f-d0894a5b0222
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-11-20
Last Modified Date: 2015-11-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Microsoft Security Intelligence Report (1H2015) analyzes targeted activity by STRONTIUM (aka APT28/Fancy Bear) — detailing reconnaissance, spear-phishing, zero-day and known exploit usage, backdoor tooling (CORESHELL/XAPS), lateral movement (custom Mimikatz), and USB/air-gap exfiltration — and surveys industry-wide vulnerabilities, exploit kit trends (Angler, Nuclear), and prevalent malware campaigns (e.g., Win32/Banload banking malware in Brazil), providing IOCs and defensive guidance.
