logo

APT28__2017__New_Xagent_Mac_Malware_Linked_with_the_APT28_Bitdefender_Labs.pdf

ID: e940d7d7-9331-48ea-86bf-cb7e450e4a1d

STIX ID: report--e940d7d7-9331-48ea-86bf-cb7e450e4a1d

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2017-02-20

Last Modified Date: 2017-02-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** The report describes the discovery and preliminary analysis of a macOS Xagent backdoor linked to APT28 (Sofacy), detailing modular espionage capabilities (filesystem access, keylogging, remote shell, screenshots), the ability to exfiltrate iPhone backups, use of the Komplex downloader for delivery, anti-debugging checks, and C2 infrastructure that impersonates Apple domains; a full technical paper with IOCs is promised.