LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0045: ADVSTORESHELL

ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase. [1] [2]

EnterpriseS0045MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

ADVSTORESHELL is a Windows spying backdoor documented by ATT&CK as used by APT28 between at least 2012 and 2016 for long-term espionage after reconnaissance identifies targets of interest. Its value to defenders is not a single malware signature; it is the pattern of durable access, host discovery, credential collection via keylogging, local staging, encrypted or encoded command-and-control, and scheduled exfiltration.

Executive priority

Treat this as an espionage-oriented backdoor case study for resilience planning: can the organization prove it would notice a Windows host quietly persisting, surveying the environment, collecting credentials/data, and exfiltrating over web-like C2? Priority should go to evidence quality across endpoint, registry, process execution, and network egress—not just malware blocking—because the ATT&CK relationships emphasize stealth, persistence, collection, and exfiltration behaviors.

Technical view

ATT&CK provides no official detection text for ADVSTORESHELL, so SOC validation should be behavior-led from the relationships: Windows Registry query/modification, Run Key/Startup Folder and COM hijacking persistence, rundll32 proxy execution, command shell activity, process/system/file/peripheral discovery, keylogging indicators, local data staging, archive/custom archive behavior, file deletion, scheduled transfer, and C2 over web protocols with standard encoding and symmetric/asymmetric cryptography. IR teams should preserve host artifacts and network records before containment where feasible, because file deletion and obfuscation are part of the mapped behavior set.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry, especially cmd.exe and rundll32.exe activity
  • Windows Registry auditing or EDR visibility for queried/modified keys, Run Keys, Startup Folder references, and COM-related registry changes
  • File system telemetry for staging directories, archive creation, custom-looking compressed/encrypted files, and suspicious deletion activity
  • Network proxy, firewall, DNS, TLS, and web request logs for unusual outbound C2-like communications and scheduled transfer patterns
  • Endpoint security alerts or behavioral telemetry related to keylogging, input capture, or suspicious API use

Detection direction

  • Build detections around chained behavior rather than a single indicator: persistence plus discovery plus staging/exfiltration is more meaningful than any one event alone.
  • Tune rundll32, command shell, Registry, and COM hijacking analytics against known administrative and software-management activity to reduce false positives.
  • Review whether web egress monitoring can detect unusual encoded or encrypted payload patterns without relying on decrypting all traffic.
  • Validate that scheduled or periodic outbound transfers from endpoints are visible in proxy/firewall telemetry and can be correlated to host process context.
  • Use the APT28 relationship as threat-intelligence context for historical tradecraft, not as proof of current activity or attribution in a local incident.

Mitigation priorities

  • Prioritize hardening and monitoring of Windows persistence surfaces: Registry Run Keys, Startup folders, and COM object references.
  • Limit unnecessary command shell and rundll32 abuse opportunities through least privilege, application control, and monitored administrative workflows where appropriate.
  • Improve egress governance so endpoints cannot freely communicate to unapproved external web destinations without logging and review.
  • Protect credentials by reducing exposure on workstations, monitoring for keylogging-like behavior, and accelerating credential reset decisions during confirmed compromise.
  • Ensure incident response playbooks include preservation of registry hives, process history, staged files, deleted-file evidence where available, and network logs.
Additional notes and limits

The strongest decision value is coverage assessment: ADVSTORESHELL maps to a broad espionage workflow across discovery, persistence, credential access, collection, command-and-control, stealth, and exfiltration. Because no official detection guidance is supplied, defenders should translate the related ATT&CK techniques into local data-source requirements and testable analytic hypotheses.

This take is limited to the supplied ATT&CK fields, references, and relationships. ATT&CK lists Windows as the malware platform and provides historical use by APT28 from at least 2012 to 2016, but does not provide current exploitation claims, indicators, detailed procedures, or official detections for this object. Local telemetry, asset criticality, and incident evidence are required to assess exposure or activity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

ADVSTORESHELL

ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase. [1] [2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

23 rows
DomainIDNameRelationship / procedure
EnterpriseT1546.015Component Object Model HijackingSub-technique

Some variants of ADVSTORESHELL achieve persistence by registering the payload as a Shell Icon Overlay handler COM object.[2]

EnterpriseT1082System Information Discovery

ADVSTORESHELL can run Systeminfo to gather information about the victim.[2][3]

EnterpriseT1056.001KeyloggingSub-technique

ADVSTORESHELL can perform keylogging.[2][3]

EnterpriseT1132.001Standard EncodingSub-technique

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding.[1]

EnterpriseT1218.011Rundll32Sub-technique

ADVSTORESHELL has used rundll32.exe in a Registry value to establish persistence.[3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.[1][2][3]

EnterpriseT1560Archive Collected Data

ADVSTORESHELL encrypts with the 3DES algorithm and a hardcoded key prior to exfiltration.[2]

EnterpriseT1070.004File DeletionSub-technique

ADVSTORESHELL can delete files and directories.[2]

EnterpriseT1074.001Local Data StagingSub-technique

ADVSTORESHELL stores output from command execution in a .dat file in the %TEMP% directory.[2]

EnterpriseT1029Scheduled Transfer

ADVSTORESHELL collects, compresses, encrypts, and exfiltrates data to the C2 server every 10 minutes.[2]

EnterpriseT1057Process Discovery

ADVSTORESHELL can list running processes.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

ADVSTORESHELL can create a remote shell and run a given command.[2][3]

EnterpriseT1083File and Directory Discovery

ADVSTORESHELL can list files and directories.[2][3]

EnterpriseT1573.001Symmetric CryptographySub-technique

A variant of ADVSTORESHELL encrypts some C2 with 3DES.[3]

EnterpriseT1071.001Web ProtocolsSub-technique

ADVSTORESHELL connects to port 80 of a C2 server using Wininet API. Data is exchanged via HTTP POSTs.[1]

EnterpriseT1012Query Registry

ADVSTORESHELL can enumerate registry keys.[2][3]

EnterpriseT1120Peripheral Device Discovery

ADVSTORESHELL can list connected devices.[2]

EnterpriseT1112Modify Registry

ADVSTORESHELL is capable of setting and deleting Registry values.[3]

EnterpriseT1027Obfuscated Files or Information

Most of the strings in ADVSTORESHELL are encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed. API function names are also reversed, presumably to avoid detection in memory.[1][3]

EnterpriseT1560.003Archive via Custom MethodSub-technique

ADVSTORESHELL compresses output data generated by command execution with a custom implementation of the Lempel–Ziv–Welch (LZW) algorithm.[2]

EnterpriseT1106Native API

ADVSTORESHELL is capable of starting a process using CreateProcess.[3]

EnterpriseT1573.002Asymmetric CryptographySub-technique

A variant of ADVSTORESHELL encrypts some C2 with RSA.[3]

EnterpriseT1041Exfiltration Over C2 Channel

ADVSTORESHELL exfiltrates data over the same channel used for C2.[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
075eb3f8c5652c97...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle075eb3f8c565…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  2. [2]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  3. [3]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  4. [4]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  5. [5]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  6. [6]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  7. [7]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  8. [8]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  9. [9]
    mitre-attackS0045
    Open source URL
  10. [10]
    mitre-attackS0045
    Open source URL
  11. [11]
    mitre-attackS0045
    Open source URL
  12. [12]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  13. [13]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  14. [14]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  15. [15]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  16. [16]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  17. [17]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  18. [18]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  19. [19]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  20. [20]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  21. [21]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  22. [22]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  23. [23]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  24. [24]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  25. [25]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  26. [26]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  27. [27]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  28. [28]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  29. [29]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  30. [30]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  31. [31]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  32. [32]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  33. [33]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  34. [34]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  35. [35]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  36. [36]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  37. [37]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  38. [38]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  39. [39]
    Securelist Sofacy Feb 2018

    Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.

    Open source URL
  40. [40]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  41. [41]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  42. [42]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  43. [43]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  44. [44]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  45. [45]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  46. [46]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  47. [47]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  48. [48]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  49. [49]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  50. [50]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  51. [51]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  52. [52]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  53. [53]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  54. [54]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  55. [55]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  56. [56]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  57. [57]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  58. [58]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  59. [59]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  60. [60]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  61. [61]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  62. [62]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  63. [63]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  64. [64]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  65. [65]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  66. [66]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  67. [67]
    Kaspersky Sofacy

    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.

    Open source URL
  68. [68]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  69. [69]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  70. [70]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  71. [71]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  72. [72]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  73. [73]
    Bitdefender APT28 Dec 2015

    Bitdefender. (2015, December). APT28 Under the Scope. Retrieved February 23, 2017.

    Open source URL
  74. [74]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

  75. [75]
    ESET Sednit Part 2

    ESET. (2016, October). En Route with Sednit - Part 2: Observing the Comings and Goings. Retrieved November 21, 2016.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.