logo

APT28__2016__eset-sednit-part-2.pdf

ID: dc7e263f-d97d-43aa-ba65-9d7e2fb75e28

STIX ID: report--dc7e263f-d97d-43aa-ba65-9d7e2fb75e28

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-10-24

Last Modified Date: 2016-10-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's whitepaper documents Sednit (APT28/Fancy Bear) espionage operations since 2014, analyzing three core tools: Xagent (modular multi‑platform backdoor with HTTP and email C2), Sedreco (plugin-capable Windows backdoor using file-buffered async C2), and Xtunnel (TLS-wrapped pivot/proxy for reaching internal hosts). The report includes source-code analysis, communication protocols, rollout/persistence workflows, IOCs (hashes, domains, IPs, filenames, mutexes, registry keys), and observed use against high-value geopolitical targets.