Skip to content

CORESHELL

Sofacy is a malware family associated with the Russian state-linked threat actor APT28, also known as Fancy Bear, Sednit, and STRONTIUM.

Profile source: Mallory opens in a new tab

CORESHELL

Family profile

Sofacy is a malware family associated with the Russian state-linked threat actor APT28, also known as Fancy Bear, Sednit, and STRONTIUM. In the provided reporting, “Sofacy” also refers to the group’s early first-stage implant from 2011–2012, which FireEye dubbed SOURFACE. The content links Sofacy/APT28 to long-running cyber espionage operations targeting governments, militaries, defense contractors, NATO-aligned entities, security organizations, and Ukraine-related targets.

The malware ecosystem associated with Sofacy expanded over time. The content states that after the early Sofacy/SOURFACE implant, APT28 added CORESHELL, CHOPSTICK (also referred to as SPLM/XAgent in one source), JHUHUGIT, and AZZY. FireEye described SOURFACE as a downloader, EVILTOSS as a backdoor providing remote access, and CHOPSTICK as a modular implant used to extend espionage functionality. Once access was established, operators reportedly deployed additional backdoors, USB stealers, and tools such as Mimikatz for lateral movement.

Capabilities directly described in the content include remote access, access to victim file systems and registries, network resource enumeration, process creation, keylogging, access to stored credentials, shellcode execution, encrypted data exfiltration using an RSA public key, and collection from removable media via USB stealer modules. A 2015 campaign description notes Sofacy used multi-backdoor packages for resilience and rapidly recompiled and redeployed malware after detection.

Observed infection and execution methods include spear-phishing emails with themed lures and malicious attachments, fake domains tied to defense events, and exploitation of multiple zero-days in Microsoft Office, Java, Adobe Flash Player, and Windows. The content specifically mentions CVE-2015-2590 being used to deliver JHUHUGIT. CORESHELL is described as being installed via rundll32 with exports named "init" or "InitW," and APT28 is also noted as executing CHOPSTICK via rundll32.

Network and C2 behavior described in the content includes CORESHELL communications over HTTP, Base64-encoded C2 messages, and encryption with custom stream ciphers using six-byte or eight-byte keys. One AZZY 4.3-related helper DLL reportedly used WinINet, connected over port 80, used the user-agent string "MSIE 8.0," and sent HTTP POST requests to "/store/." Hardcoded infrastructure mentioned for AZZY-related components includes intelnetservice[.]com, intelsupport[.]net, drivres-update[.]info, and softupdates[.]info.

Persistence and host artifacts directly mentioned include installation of msdeltemp.dll under %LOCAL_APPDATA%\Microsoft\Windows or %TEMP%, creation of the Run key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\StartUpChekTemp to launch RUNDLL32.EXE against msdeltemp.dll, and USB stealer stash directories under %MYPICTURES%\%volume serial number%. A USB stealer configuration file named NvCpld.dat is also mentioned.

Specific malware samples and artifacts cited in the content include AZZY sample MD5 a96f4b8ac7aa9dbf4624424b7602d4f7, replacement AZZY sample MD5 9d2f9e19db8c20dc0d20d50869c7a373, downloader msdeltemp.dll MD5 ce8b99df8642c065b6af43fde1f786a3, external helper DLL tf394kv.dll MD5 8c4d896957c36ec4abeb07b2802268b9, AZZY dropper MD5 c3ae4a37094ecfe95c2badecf40bf5bb, older downloader DLL MD5 f6f88caf49a3e32174387cacfa144a89, and USB stealer DLL MD5 8b238931a7f64fddcad3057a96855f6c.

Aliases directly supported by the content for this malware include CORESHELL and SOURFACE.

Reported operators

Threat actors

1 named in public reporting
APT28

It used a downloader tool that FireEye dubbed "SOURFACE", a backdoor labelled "EVILTOSS" that gives hackers remote access and a flexible modular implant called "CHOPSTICK" to enhance functionality of the espionage software.

MITRE ATT&CK

CORESHELL in ATT&CK

24 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.