New Sofacy Attacks Against US Government Agency
ID: 43f3239d-6be2-47ae-a834-8c69756c2d5e
STIX ID: report--43f3239d-6be2-47ae-a834-8c69756c2d5e
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-06-17
Last Modified Date: 2016-06-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 documents a Sofacy (APT28) spear-phishing campaign targeting a U.S. government agency where a weaponized RTF exploiting CVE-2015-1641 dropped a loader (btocache.dll) and a Carberp-variant payload (svchost.dll). The report highlights a novel persistence method that triggers the DLL when Microsoft Office applications are opened, describes the malware's beaconing and command-and-control behavior (including C2 domains/IPs and encrypted POST payloads containing system/process info), and provides sample hashes and indicators for detection and investigation.
