| X-Agent | |
|---|---|
| Type | Spyware |
| Authors | Fancy Bear[1] |
| Technical details | |
| Platform | Windows, Linux,iOS,Android |
X-Agent orXAgent is a spyware andmalware program designed to collect and transmit hacked files from machines running Windows, Linux, iOS, or Android, to servers operated by hackers. It employsphishing attacks and the program is designed to "hop" from device to device.[2][3][4] In 2016,CrowdStrike identified anAndroid variant of the malware for the first time, and claimed that the malware targeted members of the Ukrainian military by distributing an infected version of an app to controlD-30 Howitzer artillery.[1] TheUkrainian army denied CrowdStrike's report and stated that losses of Howitzer artillery pieces had "nothing to do with the stated cause".[5]
Slovak computer security companyESET obtained the X-Agent source code in 2015 and described its inner workings in a report released in October 2016.[6]
A USgrand jury indictment charges that agents of the Russian GRU in Moscow "developed, customized and monitored X-Agent malware used to hack the DCCC [Democratic Congressional Campaign Committee] and DNC [Democratic National Committee] networks beginning in or around April 2016".[7]
CrowdStrike associates the use of X-Agent with an actor we call FANCY BEAR. This actor to date is the exclusive operator of the malware