logo

APT28__2016__eset-sednit-part3.pdf

ID: 9b26e62c-0d47-407a-a6c0-c01afc322056

STIX ID: report--9b26e62c-0d47-407a-a6c0-c01afc322056

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2016-10-14

Last Modified Date: 2016-10-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This ESET whitepaper ("En Route with Sednit — Part 3") documents Downdelph, a lightweight Delphi downloader used by the Sednit/APT28 threat actor, detailing its architecture, encrypted configuration and C2 workflow, rare targeted deployments, advanced persistence via a previously undocumented MBR bootkit and a Windows rootkit (minifilter/SSDT variants), and provides associated indicators of compromise (hashes, filenames, registry keys, domains, IPs) to aid detection and response.