Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog
ID: 8dc2cb21-1fbb-4b0f-ba57-e1f6b22ae69c
STIX ID: report--8dc2cb21-1fbb-4b0f-ba57-e1f6b22ae69c
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2018-06-07
Last Modified Date: 2018-06-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Unit 42 blog documents Sofacy's parallel attack campaigns in 2018 that broadly target government and diplomatic organizations via spear-phishing and weaponized Office documents. The actor delivered the Zebrocy downloader in multiple language variants and, in at least one instance, deployed the open-source Koadic post-exploitation framework; the report highlights DDE-based document abuse, unique user-agent strings, C2 infrastructure, and provides extensive IoCs for detection.
