logo

APT28__2015__Bitdefender_In-depth_analysis_of_APT28_The_Political_Cyber-Espionage.pdf

ID: c41fbc92-b592-485b-9747-068c2f50e568

STIX ID: report--c41fbc92-b592-485b-9747-068c2f50e568

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-12-17

Last Modified Date: 2015-12-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender provides a technical analysis of APT28 (Sofacy) operations: large-scale targeted IP scanning (millions of addresses with ~1.7M vulnerable IPs in Ukraine during one campaign), multi-stage infection chains (spearphishing, exploit kits, first-stage downloader runrun.exe, second-stage backdoor advstoreshell.dll), supporting tools (xp.exe privilege escalation, run.exe password dumper, svehost.exe proxy, pr.dll modular exfiltration), C2 architecture and a Django-managed scan/bot infrastructure; the report includes victimology (political figures, government, aerospace), IoCs, custom crypto/obfuscation details and evidence of data collection and exfiltration that support attribution to Russian-speaking operators.