logo

New Sofacy Attacks Against US Government Agency

ID: 43f3239d-6be2-47ae-a834-8c69756c2d5e

STIX ID: report--43f3239d-6be2-47ae-a834-8c69756c2d5e

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-06-17

Last Modified Date: 2016-06-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 documents a Sofacy (APT28) spear-phishing campaign targeting a U.S. government agency where a weaponized RTF exploiting CVE-2015-1641 dropped a loader (btocache.dll) and a Carberp-variant payload (svchost.dll). The report highlights a novel persistence method that triggers the DLL when Microsoft Office applications are opened, describes the malware's beaconing and command-and-control behavior (including C2 domains/IPs and encrypted POST payloads containing system/process info), and provides sample hashes and indicators for detection and investigation.