Sofacy Hacker Group
Sofacy hacker group, popularly known as “Fancy Bear”, is a highly active cyber espionage group who has been actively targeting users since at least 2007. It is believed that the Sofacy hacker group is associated with the Russian military intelligence agency GRU. The infamous Sofacy hacker group has multiple other names such as APT28, Pawn Storm, Tsar Team, STRONTIUM, Sednit, Swallowtail, etc. At the time of inception, the Fancy Bear’s hacking methods comprise of traditional hacking skills such as information-stealing espionage campaigns, phishing, and messages, etc. This group is popularly known for threatening a wide variety of organizations across the world.
Sofacy hacker group or Fancy Bear has been targeting government, aerospace, defense, media, energy and security organizations. It is believed that the group has attacked multiple government organizations such as German parliament, the White House, the World Anti-Doping Agency (WADA), Democratic National Committee, Organization for Security and Co-operation in Europe, the Ukrainian military, and many others. Sofacy hacker group is a highly active and classified APT (Advanced Persistent Threat). The group has been in the news during the 2016 US presidential election. It is claimed that two cyber-espionage groups i.e. APT28 and APT29 compromised political targets.
Since its inception, Sofacy hacker group is focused on collecting intelligence information that would be useful to a government; as it is pretty much clear from their targets. It is observed that the group has been targeting numerous sectors across the world, but most of their targets comprise of military and defense ministries. Being a conventional hacker group, they typically use phishing emails or messages to hack their victim’s device (computer or laptop or mobile). Sofacy hacker group is infamously known for registering and using fake domains that look like a legitimate one. It initiates the process of spoofing that will further make the user believe that he or she is visiting a legitimate website. This results in harvesting the user’s credentials such as password, date of birth, address, social security number, and other personal information.
The Sofacy hacker group has its own arsenal which comprises of a diversified set of malware tools. The hacking group posses an extensive toolkit that includes Trojans, backdoors, double-agent software and surveillance systems. Sofacy hacker group has recently linked to the first case of UEFI rootkit detected in the wild. To mention a few malware tools used by the Fancy bear are Trojan.Sofacy, Infostealer.Sofacy, Trojan.Zekapab, Backdoor.Zekapab, etc.












