APT28__2015__R9b_FSOFACY_0.pdf
ID: 5c6c0a87-fd20-40f8-8910-650ab0430737
STIX ID: report--5c6c0a87-fd20-40f8-8910-650ab0430737
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-05-11
Last Modified Date: 2015-05-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
root9B reports detection of a pre-positioned Sofacy/APT28 campaign targeting financial institutions (notably a UAE bank and other global banks) that used fake banking domains and spear-phishing to stage attacks; investigators recovered multiple zero-day malware samples (SHA1 hashes listed) and a C2 IP (176.31.112.10) and enumerated ~250 malicious domains, attributing high sophistication and likely Russian intelligence linkage while recommending blocking the provided hashes and C2 communications.
