logo

APT28__2018__Sofacy_Attacks_Multiple_Government_Entities.pdf

ID: 62458bc1-388c-4de2-bfd0-359c4131e71e

STIX ID: report--62458bc1-388c-4de2-bfd0-359c4131e71e

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2018-03-02

Last Modified Date: 2018-03-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports that the Sofacy (APT28) threat actor conducted a targeted spear-phishing campaign against multiple Ministries of Foreign Affairs in early 2018 using a macro-laden Excel attachment which decodes and drops a loader that installs a SofacyCarberp DLL; the malware performs reconnaissance, browser injection, screenshot capture and HTTPS C2 communications (cdnverify.net) and persists via a UserInitMprLogonScript entry — the blog includes technical analysis, IOCs (SHA256s, domain, subject, filename) and links to defensive coverage.