PULSE NAME
Sofacy APT hits high profile targets
WHITE Sofacy AlienVault 2015-12-04 Modified: 2017-03-06
13
IOCs
MEDIUM VOLUME
Sofacy (also known as “Fancy Bear”, “Sednit”, “STRONTIUM” and “APT28”) is an advanced threat group that has been active since around 2008, targeting mostly military and government entities worldwide, with a focus on NATO countries. More recently, we have also seen an increase in activity targeting Ukraine. In the months leading up to August, the Sofacy group launched several waves of attacks relying on zero-day exploits in Microsoft Office, Oracle Sun Java, Adobe Flash Player and Windows itself. For instance, its JHUHUGIT implant was delivered through a Flash zero-day and used a Windows EoP exploit to break out of the sandbox. The JHUHUGIT implant became a relatively popular first stage for the Sofacy attacks and was used again with a Java zero-day (CVE-2015-2590) in July 2015.
Indicators of Compromise (13)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
domain drivres-update.info 2015-12-04
domain softupdates.info 2015-12-04
domain intelsupport.net 2015-12-04
FileHash-MD5 8b238931a7f64fddcad3057a96855f6c 2015-12-04
FileHash-MD5 ce151285e8f0e7b2b90162ba171a4b90 2015-12-04
FileHash-MD5 8c4d896957c36ec4abeb07b2802268b9 2015-12-04
FileHash-MD5 a96f4b8ac7aa9dbf4624424b7602d4f7 2015-12-04
FileHash-MD5 c3ae4a37094ecfe95c2badecf40bf5bb 2015-12-04
FileHash-MD5 ce8b99df8642c065b6af43fde1f786a3 2015-12-04
FileHash-MD5 9d2f9e19db8c20dc0d20d50869c7a373 2015-12-04
FileHash-MD5 f6f88caf49a3e32174387cacfa144a89 2015-12-04
FileHash-MD5 0369620eb139c3875a62e36bb7abdae8 2015-12-04
domain intelnetservice.com 2015-12-04