logo

2021-05_FancyBear

ID: 5ccaf2a4-6866-494d-b94f-e803b2c3dc4e

STIX ID: report--5ccaf2a4-6866-494d-b94f-e803b2c3dc4e

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2021-05-28

Last Modified Date: 2021-05-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cluster25 report analyzes a previously unreported APT28 implant called "SkinnyBoy," describing a multi-stage spear-phishing campaign that delivers a DLL downloader, a Base64‑overlaid dropper (tdp1.exe), a launcher (devtmrn.exe) and an implant DLL (TermSrvClt.dll). It documents persistence mechanisms, data-collection and exfiltration to C2 (updaterweb.com/getstatpro.com and listed IPs), provides YARA rules and extensive IOCs (file hashes, domains, IPs) and maps observed behaviors to ATT&CK techniques while attributing the activity to APT28 with medium-high confidence.