CORESHELL
MITRE ATT&CK: S0137 View on attack.mitre.org
Aliases: Sofacy, SOURFACE, CORESHELL
- First seen
- 2007-01-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 21 (2 malicious)
- Last IoC activity
- 2026-08-21 16:34:16
- Profile updated
- 2026-07-07 12:42:59
Targeted industries: defense-and-aerospace government-and-public-sector media-and-entertainment
Targeted regions: country_code:us country_code:de country_code:fr
Context
CORESHELL is a downloader used by APT28. The older versions of this malware are known as SOURFACE and newer versions as CORESHELL.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to CORESHELL (S0137). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | wellnessmedcare.org | 2026-08-21 | 1 |
| hostname | wellnesscaremed.com | 2026-07-17 | 1 |
Detection coverage
- 1 YARA rules
- 281 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Mail Protocols (attack-pattern)
- Standard Encoding (attack-pattern)
- Local Storage Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Rundll32 (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Symmetric Cryptography (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Detection rules
- SEKOIA_Apt_Sofacy_Graphitemalware_Generic (yara-rule)
Reports & references
- Kaspersky — 83930 (report)
- Kaspersky — 72924 (report)
- contagiodump.blogspot.de — Russian Apt Apt28 Collection Of Samples (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Coreshell (report)
- Mandiant — Rpt Apt28 (report)
- malware-reversing.com — 3 Disclosure Of Another 0Day Malware (report)
- malware.prevenity.com — Malware Info (report)
- Mandiant — Apt28 Center Of Storm 2017 (report)
- web.archive.org — Rpt Apt28 (report)
- MITRE ATT&CK — S0137 (report)