logo

PowerPoint Presentation

ID: e7e27165-d4b7-4e7e-9009-b9110bf690bc

STIX ID: report--e7e27165-d4b7-4e7e-9009-b9110bf690bc

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-06-16

Last Modified Date: 2016-06-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Sednit (APT28/Fancy Bear) operations and tooling used in targeted espionage against diplomatic, government and political entities: it documents phishing-delivered SEDKIT exploit chains, SEDUPLOADER/SEDRECO/XAGENT backdoors, XTUNNEL proxy, the DOWNDELPH Delphi downloader and an advanced bootkit/rootkit persistence stack, includes decrypted configurations, C2/proxy server software, email-based C2 protocols and examples of 0-day usage, and discusses development practices and links to crimeware code.