APT28__2014__Google-Aquarium-Clean.pdf
ID: f4065271-1f9b-4313-80a9-cba51dcaf47f
STIX ID: report--f4065271-1f9b-4313-80a9-cba51dcaf47f
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2017-02-14
Last Modified Date: 2017-02-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Peering Into the Aquarium (Google Security Team, Sept 5, 2014) is a detailed technical analysis of the Sofacy first-stage implant and the X-Agent second-stage toolkit used by a sophisticated state-sponsored actor targeting former Soviet republics, NATO members and Western Europe; it documents loader internals, persistence mechanisms, network/C2 protocols (HTTP, SMTP/POP3), air-gapped USB-based exfiltration, sample hashes, domains/IPs, and detection signatures (Yara/Clam).
