logo

APT28__2015__R9b_FSOFACY_0.pdf

ID: 5c6c0a87-fd20-40f8-8910-650ab0430737

STIX ID: report--5c6c0a87-fd20-40f8-8910-650ab0430737

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-05-11

Last Modified Date: 2015-05-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
root9B reports detection of a pre-positioned Sofacy/APT28 campaign targeting financial institutions (notably a UAE bank and other global banks) that used fake banking domains and spear-phishing to stage attacks; investigators recovered multiple zero-day malware samples (SHA1 hashes listed) and a C2 IP (176.31.112.10) and enumerated ~250 malicious domains, attributing high sophistication and likely Russian intelligence linkage while recommending blocking the provided hashes and C2 communications.