logo

APT28__2015__FSOFACY.pdf

ID: bc2f7579-0bb0-4cb0-9058-e62ea7af9cec

STIX ID: report--bc2f7579-0bb0-4cb0-9058-e62ea7af9cec

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2015-05-11

Last Modified Date: 2015-05-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
root9B reports discovery of a pre-positioned Sofacy/APT28 campaign targeting financial institutions (notably a UAE bank and Bank of America-like domains) that leveraged fake domains, spear-phishing and multiple zero-day malware samples; analysts recovered SHA1 hashes, a C2 IP (176.31.112.10), and an extensive list of malicious domains and used tradecraft errors to attribute activity to Russian-affiliated operators and to warn potential victims prior to campaign execution.