APT28__2014__tactical-intelligence-bulletin---sofacy-phishing-.pdf
ID: f977a253-a102-4fc2-8da5-72a38ca32d9f
STIX ID: report--f977a253-a102-4fc2-8da5-72a38ca32d9f
Threat Score
78/100
Uploaded: 2026-08-07
Published Date: 2014-10-28
Last Modified Date: 2014-10-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PwC Tactical Intelligence Bulletin documents an active Sofacy (APT) phishing campaign (2014-10-22) that uses domain impersonation, obfuscated JavaScript redirects and fake login pages to harvest credentials and deliver malware; the report includes extensive domain IOC lists, example Snort signatures, background on the group's malware, targeted sectors (diplomatic, defence, energy, news, web services), and recommended detection/mitigation steps.
