2021-05_FancyBear
ID: 5ccaf2a4-6866-494d-b94f-e803b2c3dc4e
STIX ID: report--5ccaf2a4-6866-494d-b94f-e803b2c3dc4e
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2021-05-28
Last Modified Date: 2021-05-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cluster25 report analyzes a previously unreported APT28 implant called "SkinnyBoy," describing a multi-stage spear-phishing campaign that delivers a DLL downloader, a Base64‑overlaid dropper (tdp1.exe), a launcher (devtmrn.exe) and an implant DLL (TermSrvClt.dll). It documents persistence mechanisms, data-collection and exfiltration to C2 (updaterweb.com/getstatpro.com and listed IPs), provides YARA rules and extensive IOCs (file hashes, domains, IPs) and maps observed behaviors to ATT&CK techniques while attributing the activity to APT28 with medium-high confidence.
