PULSE NAME
2018 Sofacy Activity
WHITE Sofacy AlienVault 2018-03-09 Modified: 2018-03-22
7
IOCs
LOW VOLUME
Sofacy, also known as APT28, Fancy Bear, and Tsar Team, is a prolific, well resourced, and persistent adversary. They are sometimes portrayed as wild and reckless, but as seen under our visibility, the group can be pragmatic, measured, and agile. Our previous post on their 2017 activity stepped away from the previously covered headline buzz presenting their association with previously known political hacks and interest in Europe and the US, and examines their under-reported ongoing activity in middle east, central asia, and now a shift in targeting further east, including China, along with an overlap surprise. There is much understated activity that can be clustered within this set and overlap in APT activity. Here, we examine current deployment, code, cryptography, and targeting.
Indicators of Compromise (7)
All FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 452ed4c80c1d20d111a1dbbd99d649d5 2018-03-09
FileHash-MD5 86146d38b738d5bfaff7e85a23dcc53e 2018-03-09
FileHash-MD5 973ff7eb7a5b720c5f6aafe4cd0469d5 2018-03-09
FileHash-MD5 bd3e9f7e65e18bb9a7c4ff8a8aa3a784 2018-03-09
FileHash-MD5 cc9e6578a47182a941a478b276320e06 2018-03-09
FileHash-MD5 efd8a516820c44ddbf4cc8ed7f30df9c 2018-03-09
FileHash-MD5 ff0e4f31a6b18b676b9518d4a748fed1 2018-03-09