APT28__2018__Sofacy_Attacks_Multiple_Government_Entities.pdf
ID: 62458bc1-388c-4de2-bfd0-359c4131e71e
STIX ID: report--62458bc1-388c-4de2-bfd0-359c4131e71e
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2018-03-02
Last Modified Date: 2018-03-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports that the Sofacy (APT28) threat actor conducted a targeted spear-phishing campaign against multiple Ministries of Foreign Affairs in early 2018 using a macro-laden Excel attachment which decodes and drops a loader that installs a SofacyCarberp DLL; the malware performs reconnaissance, browser injection, screenshot capture and HTTPS C2 communications (cdnverify.net) and persists via a UserInitMprLogonScript entry — the blog includes technical analysis, IOCs (SHA256s, domain, subject, filename) and links to defensive coverage.
