Netskope Threat Labs

CHOPSTICK

ATP Sandbox Adv. HeuristicsAVNetskope IPS

CHOPSTICK is a family of modular backdoors used by APT28 since at least 2012, usually dropped on victims as second stage malware. It has both Windows and Linux variants, and the US Department of Justice indictment against GRU officers references the family's use.

First seen
March 2022
Last seen
September 2026
ChopstickXAgent

19 techniques across 7 tactics.

TA0002 Execution

  • T1059Command and Scripting Interpreter

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1497Virtualization/Sandbox Evasion

TA0007 Discovery

TA0008 Lateral Movement

  • T1091Replication Through Removable Media

TA0009 Collection

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Document-Excel.Backdoor.Chopstick
Document-Excel.Trojan.XAgent
Document-Word.Trojan.XAgent
MAC.IOS.XAgent.A
MacOS.Trojan.XAgent
Win32.Trojan.XAgent