logo

Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog

ID: 8dc2cb21-1fbb-4b0f-ba57-e1f6b22ae69c

STIX ID: report--8dc2cb21-1fbb-4b0f-ba57-e1f6b22ae69c

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2018-06-07

Last Modified Date: 2018-06-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Unit 42 blog documents Sofacy's parallel attack campaigns in 2018 that broadly target government and diplomatic organizations via spear-phishing and weaponized Office documents. The actor delivered the Zebrocy downloader in multiple language variants and, in at least one instance, deployed the open-source Koadic post-exploitation framework; the report highlights DDE-based document abuse, unique user-agent strings, C2 infrastructure, and provides extensive IoCs for detection.