APT28__2015__FSOFACY.pdf
ID: bc2f7579-0bb0-4cb0-9058-e62ea7af9cec
STIX ID: report--bc2f7579-0bb0-4cb0-9058-e62ea7af9cec
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-05-11
Last Modified Date: 2015-05-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
root9B reports discovery of a pre-positioned Sofacy/APT28 campaign targeting financial institutions (notably a UAE bank and Bank of America-like domains) that leveraged fake domains, spear-phishing and multiple zero-day malware samples; analysts recovered SHA1 hashes, a C2 IP (176.31.112.10), and an extensive list of malicious domains and used tradecraft errors to attribute activity to Russian-affiliated operators and to warn potential victims prior to campaign execution.
