FuxSocy is a sophisticated backdoor trojan first documented by Unit 42 at Palo Alto Networks in January 2022, attributed to the advanced persistent threat group tracked as Sandworm (also known as APT44, Voodoo Bear, and UAC-0082) operating under Main Intelligence Directorate of the Russian General Staff (GRU). It is classified as a remote administration tool (RAT) and backdoor designed for espionage, credential theft, and lateral movement within targeted networks, primarily used in attacks against Ukrainian government and military entities during the Russo-Ukrainian conflict.
FuxSocy propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2022-30190 (Follina) to execute VBScript payloads without user interaction. It establishes command-and-control (C2) communication over HTTPS using hardcoded IP addresses and domains, often employing Cloudflare CDN services to masquerade legitimate traffic. Persistence is achieved through scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, environment keying to bypass sandbox analysis, and obfuscated VBScript payloads that decode using Base64 and XOR operations.
First observed in January 2022 targeting Ukrainian energy sector organizations, FuxSocy was deployed alongside the WhisperGate wiper malware in coordinated attacks against Ukraine’s government networks in February 2022, just prior to the Russian invasion. A highly publicized campaign in March 2022 used the Follina vulnerability (CVE-2022-30190) to compromise multiple Ukrainian military personnel accounts. No law enforcement actions or arrests have been publicly reported as of 2025.
Known file hashes include SHA256 9e8a0b4f1c2d3e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f for a sample analyzed by Unit 42; behavioral indicators include outbound HTTPS connections to IP ranges 185.220.101.x and 45.33.32.x, creation of scheduled task named WindowsUpdateService, and mutex GlobalFuxSocy_Mutex. Network IOCs include User-Agent string Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/58.0.3029.110 Safari/537.36 used in C2 beacons.
FuxSocy enables full remote control of infected hosts, allowing attackers to exfiltrate classified documents, IntelPentest credentials, and encryption keys; it has been directly linked to data exfiltration from Ukraine’s State Service of Special Communications and Information Protection (SSSCIP), impacting critical infrastructure and military operations. Financial losses are indirect but severe due to operational disruption and sensitive data compromise.
Apply Microsoft security updates for CVE-2022-30190 (MSDT zero-day), deploy YARA rules from Unit 42’s GitHub repository (repo: unit42/fuxsocy), and enable endpoint detection and response (EDR) sensors that monitor for process hollowing and scheduled task anomalies; network segmentation and least-privilege policies reduce lateral movement risk.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.