APT28__2019__A_journey_to_Zebrocy_land.pdf
ID: 68563fd1-a083-4e36-bf46-dec28645c0bf
STIX ID: report--68563fd1-a083-4e36-bf46-dec28645c0bf
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2019-05-23
Last Modified Date: 2019-05-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET details the Zebrocy Delphi backdoor campaign attributed to the Sednit (APT28) group: attackers used spearphishing with shortened URLs to deliver a multi-stage downloader chain that installs a Delphi backdoor which immediately accepts operator commands to enumerate systems, capture screenshots, harvest credentials (via credential-dumpers targeting multiple browsers and Outlook), and exfiltrate files; the report includes command descriptions, persistence/COM-hijacking techniques, IoCs (URLs and malware hashes), and mappings to MITRE ATT&CK techniques.
