logo

APT28__2014__apt28.pdf

ID: 928b712e-3d77-4db5-ab8f-ffb8c2eccef6

STIX ID: report--928b712e-3d77-4db5-ab8f-ffb8c2eccef6

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2014-10-27

Last Modified Date: 2014-10-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye profiles APT28, a persistent espionage threat active since at least 2007 that targets Georgian, Eastern European, and NATO/security-related targets. The report documents spearphishing lures and domain impersonation, technical analysis of modular malware families (SOURFACE/CORESHELL downloader, EVILTOSS backdoor, CHOPSTICK modular implant, OLDBAIT credential harvester), C2 protocols and examples, compile-time and locale metadata linking development to Russian-language build environments and Moscow/St. Petersburg working hours, and concludes the activity is consistent with Russian government-sponsored intelligence collection.