Skip to content

CORESHELL

Sofacy is an APT28-associated Windows malware family name historically used for an early-stage implant also referred to as SOURFACE, and in some reporting linked alongside the CORESHELL naming lineage.

Profile source: Mallory opens in a new tab

CORESHELL

Family profile

Sofacy is an APT28-associated Windows malware family name historically used for an early-stage implant also referred to as SOURFACE, and in some reporting linked alongside the CORESHELL naming lineage. It is part of the broader malware ecosystem used by the Russian state-linked espionage group widely tracked as APT28, Fancy Bear, Sednit, or STRONTIUM. The implant has been used in targeted cyber-espionage operations against government, military, defense, political, and security-related organizations, particularly in Europe and other regions aligned with Russian intelligence priorities.

As documented in public reporting on APT28 tradecraft, Sofacy/SOURFACE functioned as a first-stage foothold used to establish access and support follow-on deployment of more capable implants. Related APT28 tooling provided remote access and modular post-compromise functionality, and the Sofacy malware lineage is associated with encrypted and Base64-encoded command-and-control communications. CORESHELL-related variants in this lineage have been observed using custom stream ciphers for command traffic, establishing persistence through Windows autostart mechanisms, and being executed through rundll32 to proxy DLL execution. The malware family is therefore best understood as part of a staged espionage toolchain rather than a standalone commodity threat.

Operationally, Sofacy was commonly delivered in highly targeted spearphishing campaigns using themed lures and malicious attachments. Once access was established, APT28 frequently deployed additional backdoors and espionage modules to expand collection and maintain resilience. The malware family is closely associated with long-running Russian intelligence collection operations and is notable for its role in the early evolution of APT28’s intrusion toolkit.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence

Reported operators

Threat actors

1 named in public reporting
APT28

APT28_2011-09_Telus_Trojan.Win32.Sofacy.A ... APT28_2015-07_Telus_Trojan-Downloader.Win32.Sofacy.B ... APT28_2015-12_Kaspersky_Sofacy APT hits high profile targets | APT28_2014-10_Telus_Coreshell.A ... coreshell.dll

Exploited software

Vulnerabilities linked to CORESHELL

1 CVEs

MITRE ATT&CK

CORESHELL in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.