MalwareBazaar Database

This page shows some basic information the YARA rule APT_APT29_sorefang_custom_encode_decode including corresponding malware samples.

Database Entry


YARA Rule:APT_APT29_sorefang_custom_encode_decode
Author:NCSC
Description:Rule to detect SoreFang based on the custom encoding/decoding algorithm function
Firstseen:2026-04-01 10:53:51 UTC
Lastseen:never
Sightings:1

Malware Samples


The table below shows all malware samples that matching this particular YARA rule (max 1000).

Firstseen (UTC)SHA256 hashTagsSignatureReporter