PULSE NAME
STRONTIUM: A profile of a persistent and motivated adversary
WHITE Sofacy AlienVault 2015-11-19 Modified: 2017-03-06
20
IOCs
MEDIUM VOLUME
STRONTIUM has been active since at least 2007. Whereas most modern untargeted malware is ultimately profit-oriented, STRONTIUM mainly seeks sensitive information. Its primary institutional targets have included government bodies, diplomatic institutions, and military forces and installations in NATO member states and certain Eastern European countries. Additional targets have included journalists, political advisors, and organizations associated with political activism in central Asia. STRONTIUM is Microsoft’s code name for this group, following its internal practice of assigning chemical element names to activity groups; other researchers have used code names such as APT28, Sednit, Sofacy and Fancy Bear as labels for a group or groups .
Indicators of Compromise (7 / 20 total)
All domain hostname CVE
TYPEINDICATORDESCRIPTIONCREATED
domain nato-news.com 2015-11-19
domain electronicfrontierfoundation.org 2015-11-19
domain privacy-live.com 2015-11-19
domain bbc-press.org 2015-11-19
domain mail-ukr.net 2015-11-19
domain osce-press.com 2015-11-19
domain us-mg6mailyahoo.com 2015-11-19