APT28__2016__eset-sednit-part-2.pdf
ID: dc7e263f-d97d-43aa-ba65-9d7e2fb75e28
STIX ID: report--dc7e263f-d97d-43aa-ba65-9d7e2fb75e28
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-10-24
Last Modified Date: 2016-10-24
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET's whitepaper documents Sednit (APT28/Fancy Bear) espionage operations since 2014, analyzing three core tools: Xagent (modular multi‑platform backdoor with HTTP and email C2), Sedreco (plugin-capable Windows backdoor using file-buffered async C2), and Xtunnel (TLS-wrapped pivot/proxy for reaching internal hosts). The report includes source-code analysis, communication protocols, rollout/persistence workflows, IOCs (hashes, domains, IPs, filenames, mutexes, registry keys), and observed use against high-value geopolitical targets.
