DealersChoice
MITRE ATT&CK: S0243 View on attack.mitre.org
Aliases: DealersChoice
- Malware type
- exploit-kit
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:20:01
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:us country_code:fr
Context
DealersChoice is a Flash exploitation framework used by APT28.
Detection coverage
- 77 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Web Protocols (attack-pattern)
Used by threat actors
- APT28 (threat-actor)
Reports & references
- researchcenter.paloaltonetworks.com — Unit42 Sofacy Uses Dealerschoice Target European Government Agency (report)
- MITRE ATT&CK — S0243 (report)
External references
- mitre-attack — S0243
- DealersChoice
- Sofacy DealersChoice
- misp-galaxy
- misp-galaxy