Netskope Threat Labs

CORESHELL

ATP Sandbox Adv. HeuristicsAV

Sofacy (a.k.a. APT28) is a malware family associated with Russian state sponsored actors, and its downloader tooling appears at the start of espionage campaigns against governments and militaries in Europe and North America. Its implants survey infected systems, harvest credentials, and stage further tooling for operators who favor quick, opportunistic collection. The family's long association with the group's broader operations has made it one of the most documented state sponsored toolsets.

First seen
March 2022
Last seen
October 2026

11 techniques across 4 tactics.

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1082System Information Discovery
  • T1680Local Storage Discovery

TA0011 Command and Control

Alert Name
Gen:Variant.Sofacy.5
Gen:Variant.Sofacy.7
MacOS.Trojan.Sofacy
Script-JS.Trojan.Sofacy
Win32.Backdoor.Sofacy
Win32.Trojan.Sofacy
Win64.Backdoor.Sofacy
Win64.Trojan.Sofacy