logo

APT28__2019__A_journey_to_Zebrocy_land.pdf

ID: 68563fd1-a083-4e36-bf46-dec28645c0bf

STIX ID: report--68563fd1-a083-4e36-bf46-dec28645c0bf

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2019-05-23

Last Modified Date: 2019-05-23

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET details the Zebrocy Delphi backdoor campaign attributed to the Sednit (APT28) group: attackers used spearphishing with shortened URLs to deliver a multi-stage downloader chain that installs a Delphi backdoor which immediately accepts operator commands to enumerate systems, capture screenshots, harvest credentials (via credential-dumpers targeting multiple browsers and Outlook), and exfiltrate files; the report includes command descriptions, persistence/COM-hijacking techniques, IoCs (URLs and malware hashes), and mappings to MITRE ATT&CK techniques.