CHOPSTICK
S0023 · Windows, Linux
CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants.
It is tracked separately from the X-Agent for Android.
ATT&CK S0023
3 actors documented