logo

APT28__2014__Google-Aquarium-Clean.pdf

ID: f4065271-1f9b-4313-80a9-cba51dcaf47f

STIX ID: report--f4065271-1f9b-4313-80a9-cba51dcaf47f

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2017-02-14

Last Modified Date: 2017-02-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Peering Into the Aquarium (Google Security Team, Sept 5, 2014) is a detailed technical analysis of the Sofacy first-stage implant and the X-Agent second-stage toolkit used by a sophisticated state-sponsored actor targeting former Soviet republics, NATO members and Western Europe; it documents loader internals, persistence mechanisms, network/C2 protocols (HTTP, SMTP/POP3), air-gapped USB-based exfiltration, sample hashes, domains/IPs, and detection signatures (Yara/Clam).