Description
CHOPSTICK is a family of modular backdoors used by APT28 since at least 2012, usually dropped on victims as second stage malware. It has both Windows and Linux variants, and the US Department of Justice indictment against GRU officers references the family's use.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Also known as
ChopstickXAgent
MITRE ATT&CK techniques
19 techniques across 7 tactics.
TA0002 Execution
- T1059Command and Scripting Interpreter
TA0005 Stealth
TA0007 Discovery
TA0008 Lateral Movement
- T1091Replication Through Removable Media
TA0011 Command and Control
TA0112 Defense Impairment
- T1112Modify Registry
Associated groups
Alert name variants
| Alert Name |
|---|
| Document-Excel.Backdoor.Chopstick |
| Document-Excel.Trojan.XAgent |
| Document-Word.Trojan.XAgent |
| MAC.IOS.XAgent.A |
| MacOS.Trojan.XAgent |
| Win32.Trojan.XAgent |