PULSE NAME
A Look Into Fysbis: Sofacy’s Linux Backdoor
WHITE Sofacy AlienVault 2016-02-13 Modified: 2017-08-23
11
IOCs
MEDIUM VOLUME
The Sofacy group, also known as APT28 and Sednit, is a fairly well known cyber espionage group believed to have ties to Russia. Their targets have spanned all across the world, with a focus on government, defense organizations and various Eastern European governments. From these reports, we know that the group uses an abundance of tools and tactics, ranging across zero-day exploits targeting common applications such as Java or Microsoft Office, heavy use of spear-phishing attacks, compromising legitimate websites to stage watering-hole attacks, and targeting over a variety of operating systems – Windows, OSX, Linux, even mobile iOS.
Indicators of Compromise (2 / 11 total)
All FileHash-SHA256 domain FileHash-MD5 YARA
TYPEINDICATORDESCRIPTIONCREATED
YARA d2f582c70bb93bf81ff8179513402df63c245ae7 2017-08-23
YARA 55a38e3869f093256fd1deda5bdca6fdfda42905 2017-08-23