APT28__2015__cto-tib-20150420-01a.pdf
ID: c6316fbc-0fc8-48b9-8115-91062a61924d
STIX ID: report--c6316fbc-0fc8-48b9-8115-91062a61924d
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-04-20
Last Modified Date: 2015-04-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC Tactical Intelligence Bulletin reports on recent Sofacy (APT28/Fancy Bear/Pawn Storm) activity: spear-phishing that leverages browser exploits (notably CVE-2015-3043 and CVE-2015-1701) to deploy malware and harvest web-mail credentials. The bulletin provides a TLP:WHITE appendix of domains observed or suspected to be used for phishing and command-and-control, and points to Trend Micro and FireEye reporting for further technical detail and indicators.
