PowerPoint Presentation
ID: e7e27165-d4b7-4e7e-9009-b9110bf690bc
STIX ID: report--e7e27165-d4b7-4e7e-9009-b9110bf690bc
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-06-16
Last Modified Date: 2016-06-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Sednit (APT28/Fancy Bear) operations and tooling used in targeted espionage against diplomatic, government and political entities: it documents phishing-delivered SEDKIT exploit chains, SEDUPLOADER/SEDRECO/XAGENT backdoors, XTUNNEL proxy, the DOWNDELPH Delphi downloader and an advanced bootkit/rootkit persistence stack, includes decrypted configurations, C2/proxy server software, email-based C2 protocols and examples of 0-day usage, and discusses development practices and links to crimeware code.
