PULSE NAME
STRONTIUM: A profile of a persistent and motivated adversary
WHITE Sofacy AlienVault 2015-11-19 Modified: 2017-03-06
20
IOCs
MEDIUM VOLUME
STRONTIUM has been active since at least 2007. Whereas most modern untargeted malware is ultimately profit-oriented, STRONTIUM mainly seeks sensitive information. Its primary institutional targets have included government bodies, diplomatic institutions, and military forces and installations in NATO member states and certain Eastern European countries. Additional targets have included journalists, political advisors, and organizations associated with political activism in central Asia. STRONTIUM is Microsoft’s code name for this group, following its internal practice of assigning chemical element names to activity groups; other researchers have used code names such as APT28, Sednit, Sofacy and Fancy Bear as labels for a group or groups .
Indicators of Compromise (12 / 20 total)
All domain hostname CVE
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2015-1701 2015-11-19
CVE CVE-2015-5119 2015-11-19
CVE CVE-2015-7645 2015-11-19
CVE CVE-2015-1641 2015-11-19
CVE CVE-2014-1776 2015-11-19
CVE CVE-2015-4902 2015-11-19
CVE CVE-2014-3897 2015-11-19
CVE CVE-2014-6332 2015-11-19
CVE CVE-2015-2590 2015-11-19
CVE CVE-2015-2424 2015-11-19
CVE CVE-2015-2387 2015-11-19
CVE CVE-2015-3043 2015-11-19