APT28__2021__A_step-by-step_analysis_of_the_new_malware_used_by_APT28_Sofacy_called_SkinnyBoy_CYBER_GEEKS.pdf
ID: 690c9211-5d07-4ef9-85e4-bceb31b9a283
STIX ID: report--690c9211-5d07-4ef9-85e4-bceb31b9a283
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2021-10-18
Last Modified Date: 2021-10-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report provides a step‑by‑step technical analysis of the SkinnyBoy backdoor tied to APT28/Sofacy: it enumerates host information (systeminfo, tasklist), collects files from multiple user and system directories, base64-encodes the data and exfiltrates it via HTTP POST to updaterweb.com (User-Agent "Opera"), and can download and execute a secondary DLL. The analysis includes API-level traces, encoded strings and decryption keys, a SHA256 sample, and IoCs suitable for detection and response.
