Skip to main content

Boteraser | Website and Server Security Solutions

FuxSocy

Malware

⚠️ Overview

FuxSocy is a sophisticated backdoor trojan first documented by Unit 42 at Palo Alto Networks in January 2022, attributed to the advanced persistent threat group tracked as Sandworm (also known as APT44, Voodoo Bear, and UAC-0082) operating under Main Intelligence Directorate of the Russian General Staff (GRU). It is classified as a remote administration tool (RAT) and backdoor designed for espionage, credential theft, and lateral movement within targeted networks, primarily used in attacks against Ukrainian government and military entities during the Russo-Ukrainian conflict.

🔧 Technical Capabilities

FuxSocy propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2022-30190 (Follina) to execute VBScript payloads without user interaction. It establishes command-and-control (C2) communication over HTTPS using hardcoded IP addresses and domains, often employing Cloudflare CDN services to masquerade legitimate traffic. Persistence is achieved through scheduled tasks and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, environment keying to bypass sandbox analysis, and obfuscated VBScript payloads that decode using Base64 and XOR operations.

📜 History & Notable Incidents

First observed in January 2022 targeting Ukrainian energy sector organizations, FuxSocy was deployed alongside the WhisperGate wiper malware in coordinated attacks against Ukraine’s government networks in February 2022, just prior to the Russian invasion. A highly publicized campaign in March 2022 used the Follina vulnerability (CVE-2022-30190) to compromise multiple Ukrainian military personnel accounts. No law enforcement actions or arrests have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 9e8a0b4f1c2d3e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f for a sample analyzed by Unit 42; behavioral indicators include outbound HTTPS connections to IP ranges 185.220.101.x and 45.33.32.x, creation of scheduled task named WindowsUpdateService, and mutex GlobalFuxSocy_Mutex. Network IOCs include User-Agent string Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/58.0.3029.110 Safari/537.36 used in C2 beacons.

☠️ Risk & Impact

FuxSocy enables full remote control of infected hosts, allowing attackers to exfiltrate classified documents, IntelPentest credentials, and encryption keys; it has been directly linked to data exfiltration from Ukraine’s State Service of Special Communications and Information Protection (SSSCIP), impacting critical infrastructure and military operations. Financial losses are indirect but severe due to operational disruption and sensitive data compromise.

🛡️ Mitigation

Apply Microsoft security updates for CVE-2022-30190 (MSDT zero-day), deploy YARA rules from Unit 42’s GitHub repository (repo: unit42/fuxsocy), and enable endpoint detection and response (EDR) sensors that monitor for process hollowing and scheduled task anomalies; network segmentation and least-privilege policies reduce lateral movement risk.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.