APT28__2014__apt28.pdf
ID: 928b712e-3d77-4db5-ab8f-ffb8c2eccef6
STIX ID: report--928b712e-3d77-4db5-ab8f-ffb8c2eccef6
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2014-10-27
Last Modified Date: 2014-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye profiles APT28, a persistent espionage threat active since at least 2007 that targets Georgian, Eastern European, and NATO/security-related targets. The report documents spearphishing lures and domain impersonation, technical analysis of modular malware families (SOURFACE/CORESHELL downloader, EVILTOSS backdoor, CHOPSTICK modular implant, OLDBAIT credential harvester), C2 protocols and examples, compile-time and locale metadata linking development to Russian-language build environments and Moscow/St. Petersburg working hours, and concludes the activity is consistent with Russian government-sponsored intelligence collection.
