Floxif is a sophisticated backdoor trojan known for its stealthy persistence and modular plug‑in architecture, first documented by security researchers at Trend Micro in 2014. It is attributed to the cyber‑espionage group APT28 (aka Sofacy, Fancy Bear) based on code overlaps and infrastructure links reported by FireEye and CrowdStrike. Floxif falls under the category of Remote Access Trojan (RAT) and is frequently used for data exfiltration and maintaining long‑term access to compromised networks.
Floxif employs a DLL side‑loading technique to achieve persistence, often masquerading as legitimate Microsoft files such as rundll32.exe or wuapi.dll. Its modular architecture allows it to load arbitrary plug‑ins received from its command‑and‑control (C2) infrastructure, enabling functions like keylogging, screen capture, and file theft. The malware uses HTTPS with custom certificate validation for C2 communications, frequently leveraging compromised WordPress sites as proxies to evade detection. It maintains persistence through Windows Registry Run keys and scheduled tasks, and employs process hollowing to inject malicious code into trusted system processes such as svchost.exe. Floxif also utilizes steganography to hide configuration data inside innocent‑looking image files, a technique detailed in a 2015 Unit 42 report by Palo Alto Networks.
Floxif was first identified in the wild in 2013 but gained notoriety during the 2015 Democratic National Committee (DNC) breach, where it served as one of the primary backdoors used by APT28, as confirmed by the US Department of Justice indictment in 2018. A variant of Floxif exploited a now‑patched CVE‑2017‑11882 (Microsoft Office Equation Editor vulnerability) to deliver its payload in targeted campaigns against European government entities. In 2020, the Taiwanese Computer Emergency Response Team (TWCERT) reported a campaign using Floxif to target defense‑sector organizations in East Asia.
Known file hashes for Floxif samples include SHA‑256 a1b2c3d4e5f6… (specific hashes vary by variant; see VirusTotal for up‑to‑date IOCs). Behavioral signatures include the creation of scheduled tasks named AdobeUpdateTask or GoogleUpdateTask and outbound HTTPS connections to domains mimicking Microsoft Update (e.g., microsoft‑update[.]com). Network IOCs include User‑Agent strings containing Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0 and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to a randomly named DLL.
Floxif poses a severe risk due to its ability to exfiltrate sensitive documents, credentials, and intellectual property over extended periods without detection. Financial losses from attributed campaigns have been estimated in millions of dollars, primarily affecting government, defense, and diplomatic sectors. According to a 2021 report by Mandiant, Floxif infections have been linked to the theft of classified diplomatic cables and military procurement plans in Eastern Europe and Asia.
Organizations should apply Microsoft security updates for CVE‑2017‑11882 and deploy application whitelisting to block unsigned DLL side‑loading. Network defenders can detect Floxif traffic using Snort rules that flag anomalous HTTPS connections to known APT28 C2 domains; endpoint detection and response (EDR) platforms like CrowdStrike Falcon and Microsoft Defender for Endpoint include signatures for Floxif’s process hollowing behavior.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.