Security researchers have discovered a new malware called “SkinnyBoy,” which was used in phishing campaigns allegedly carried out by the Russian-speaking hacking group “APT28.” APT28 (also known as Fancy Bear, Sednit, Sofacy, Strontium, or PwnStorm) used SkinnyBoy in attacks targeting military and government organizations earlier this year.
SkinnyBoy was intended as an intermediate stage of the attack to gather information about the victim and retrieve the next payload from the C2 server.
According to threat research firm Cluster25, APT28 likely carried out this campaign in early March, targeting foreign ministries, embassies, the defense industry, and the military. Many of the victims are located in the European Union, but researchers said the activity may have also affected organizations in the United States.
Read also: Hackers lure Android users with fake antivirus and infect them with malware
SkinnyBoy is distributed via a Word document with a macro that extracts a DLL file that acts as a malware downloader.

A message with a fake invitation to an international scientific event that will take place in Spain at the end of July is used as "bait"
Opening the invitation triggers the infection chain, which begins with the extraction of a DLL that retrieves the SkinnyBoy dropper, a malicious file that downloads the main payload. Once on the system, the dropper creates persistence and moves on to extract the next payload, which is encoded in Base64 format and attached as an overlay to the executable file.
See also: iPhone: How to check if it is infected with malware and how to remove it?

This payload is deleted after it extracts two files:
- C: \ Users \% username% \ AppData \ Local \ devtmrn.exe (2a652721243f29e82bdf57b565208c59937bbb6af4ab51e7b6ba7ed270ea6bce)
- C: \ Users \% username% \ AppData \ Local \ Microsoft \ TerminalServerClient \ TermSrvClt.dll (ae0bc3358fef0ca2a103e694aa556f55a3fed4e98ba57d16f5ae7ad4ad583698)
To "keep a low profile," the malware executes these files at a later stage, after creating a persistence mechanism via a LNK file in the Windows Startup folder.
The LNK file is activated on the next reboot of the infected machine and looks for the main payload, SkinnyBoy (TermSrvClt.dll), by checking the SHA256 hashes of all files in C:\Users\%username%\AppData\Local.
SkinnyBoy's purpose is to delete information about the infected system, as well as download and execute the final payload of the attack, which remains unknown at this time.
Proposal: Chinese hackers spent 3 years developing backdoor to spy on governments
The data collection is done using systeminfo.exe and tasklist., Exx tools already present in Windows, which allow it to extract file names to specific locations:
- C: \ Users \% username% \ Desktop
- C:\Program Files – C:\Program Files (x86)
- C:\Users\% username%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
- C: \ Users \% username% \ AppData \ Roaming
- C: \ Users \% username% \ AppData \ Roaming \ Microsoft \ Windows \ Templates
- C: \ Windows – C: \ Users \ user \ AppData \ Local \ Temp
All information extracted in this way is transferred to the C2 server in an organized manner and encoded in base64 format.
As Cluster25 reports, the attacker used VPN services to purchase data for their infrastructure, a tactic hackers use to better hide their tracks.

After observing the tactics, techniques, and procedures, Cluster25 believes the SkinnyBoy implant is a new tool from the Russian APT28.
In the report it released on June 3, Cluster25 provides YARA rules for all the tools its researchers examined (SkinnyBoy dropper, launcher, and the payload itself), as well as a list of indicators of compromise that can help organizations detect the presence of the new malware.
Information source: bleepingcomputer.com
