APT28 — Threat Intelligence Wiki
    Threat Intelligence Wiki
    Article  |  Talk     Read  |  View source  |  History

    APT28

    From Threat Intelligence Wiki, the collaborative threat-actor encyclopedia
    APT28
    🐻
    Threat actor emblem (illustrative)
    Also known asFancy Bear · Sofacy · Sednit · Forest Blizzard · STRONTIUM · Iron Twilight
    Formationc. 2004
    TypeAdvanced persistent threat (state-sponsored)
    PurposeCyber espionage, information operations
    Region servedEurope, North America, Asia, Middle East
    Alleged parent org.GRU (Units 26165 / 74455)
    Attribution confidenceHigh
    Status● Active
    Notable toolsX-Agent, X-Tunnel, Zebrocy, CHOPSTICK

    APT28, also known as Fancy Bear, Sofacy, Sednit, Forest Blizzard, and STRONTIUM, is a cyber espionage group publicly attributed by multiple Western governments to Russia’s military intelligence service, the Main Directorate of the General Staff of the Armed Forces (GRU).[1] The group has been active since at least the mid-2000s and is one of the most extensively documented advanced persistent threat (APT) actors in public threat-intelligence reporting.[2]

    Unlike financially motivated intrusion sets, APT28’s operations are understood to serve Russian strategic and military intelligence objectives, and its campaigns have frequently coincided with geopolitical events, elections, and military conflicts.[3] The group maintains a family of custom malware tools, rotates infrastructure quickly, and has repeatedly incorporated newly disclosed vulnerabilities into its operations within days of public disclosure.[4]

    Aliases used by other vendors:
    Forest Blizzard (Microsoft) · STRONTIUM (Microsoft, legacy) · Fancy Bear (CrowdStrike) · Sednit (ESET) · Sofacy (Kaspersky) · Iron Twilight (Secureworks) · Pawn Storm (Trend Micro)

    Overview [edit]

    APT28 is a long-running cyber-espionage group that has conducted intelligence-collection campaigns since at least 2004.[1] Security researchers describe the group as highly capable, combining social engineering, credential theft, custom malware, abuse of legitimate cloud services, and rapid adoption of publicly disclosed vulnerabilities to obtain long-term access to targeted networks.

    Attribution [edit]

    Governments including the United States, United Kingdom, Canada, Australia, and Germany, along with the European Union, have publicly attributed APT28 activity to Russia’s GRU, citing forensic analysis, infrastructure overlap, and classified intelligence assessments.[2] Independent security vendors have separately converged on technical indicators despite tracking the group under different names.

    “Overlapping tooling, infrastructure, and targeting patterns tracked across more than a decade give this attribution a level of confidence rarely seen with other state-linked intrusion sets.”
    — paraphrased from multi-vendor threat intelligence reporting[3]

    Targets and victimology [edit]

    Reported targeting has spanned four broad categories:

    • Government — foreign ministries, executive agencies, diplomatic missions
    • Defense — aerospace firms, weapons research institutes, military logistics providers
    • Critical infrastructure — energy, transportation, and telecommunications operators
    • Media and civil society — journalists, universities, and policy think tanks

    History [edit]

    PeriodDevelopment
    2004–2007Earliest activity identified retrospectively by researchers.
    2008–2012Expansion of espionage operations against government worldwide.
    2013–2015Increased use of custom malware and zero-day vulnerabilities.
    2016Global attention following U.S. election-related operations.
    2020–2022Shift toward cloud-identity abuse and credential-based intrusion.
    2023–presentOperations against logistics sectors with evolving tradecraft.

    Notable campaigns [edit]

    PeriodCampaign / targetDescription
    2008Georgian governmentEspionage activity coinciding with the Russo-Georgian War.
    2014Public identificationFireEye publishes first detailed report naming “APT28”.[5]
    2015German BundestagSignificant parliamentary network breach via spear-phishing.[6]
    2015TV5Monde (France)Disruptive intrusion misattributed to “Cyber Caliphate”.
    2016DNC / Clinton CampaignCompromise of systems during the U.S. presidential election.[7]
    2016–2018WADA & USADATheft and leaking of athlete drug-testing records.
    2018OPCW / Spiez LabAttempted Wi-Fi sniffing operation disrupted by Dutch intelligence.[8]
    2018–2020Global brute-forceLarge-scale password-spraying detailed in 2021 NSA advisory.[9]
    2021–2023French entitiesSustained intrusion set documented by ANSSI.
    2022–presentUkraine (UAC-0001)Continuous operations against defense and emergency services.[10]
    2024Edge-router campaignUse of compromised SOHO routers as relay infrastructure.
    2022–2025Western logisticsTargeting firms coordinating aid to Ukraine; 11-nation advisory.[11]
    Jan–Feb 2026PRISMEX weaponizationRapid weaponization of CVE-2026-21509 within 24 hours.[12]
    Jan 28–30, 2026Cloud-C2 campaign72-hour operation delivering “NotDoor” VBA backdoor.[13]

    Tools and malware [edit]

    NameFunction
    X-AgentModular platform for file harvesting and reconnaissance.
    X-TunnelSecure data-transfer tool used to conceal traffic.
    ZebrocyBackdoor implemented in multiple languages to complicate detection.
    SofacyLong-running toolset for persistent access.
    CHOPSTICKCapability designed for long-term persistence.

    Infrastructure [edit]

    • Short-lived domain registrations across geographically distributed providers.
    • Use of compromised third-party servers as intermediate relays.
    • Abuse of legitimate cloud platforms (Google, Microsoft, Dropbox) for C2.

    Tactics, techniques and procedures [edit]

    TacticTechnique IDExamples
    Initial AccessT1566, T1190Spear-phishing, exploitation of public applications.
    ExecutionT1059, T1204PowerShell, user execution of payloads.
    PersistenceT1053, T1547Scheduled tasks, registry modification.
    Credential AccessT1003, T1110OS credential dumping, brute force.

    Exploited vulnerabilities [edit]

    CVEYearProductPurpose
    CVE-2023-233972023OutlookCredential theft (9.8 CVSS)
    CVE-2023-388312023WinRARInitial access via archives
    CVE-2022-301902022WindowsRemote code execution (Follina)
    CVE-2026-215092026MS OfficeRapid weaponized exploitation

    Detection and mitigation [edit]

    • Monitor for unauthorized mailbox exports and forwarding rule changes.
    • Detect unsigned executables and abnormal parent–child process relationships.
    • Enforce phishing-resistant MFA (FIDO2 keys) for all cloud identities.
    • Apply security updates promptly to all internet-facing systems.
    • APT29 (Cozy Bear) — Linked to Russia’s SVR intelligence service.
    • Sandworm (APT44) — GRU-linked group focused on disruptive OT attacks.
    • Turla — Russian group known for satellite-link hijacking.

    References [edit]

    1. Multi-government joint advisory on GRU cyber actors.
    2. Mandiant, CrowdStrike, and ESET profiling on APT28.
    3. Microsoft Threat Intelligence, “Forest Blizzard” reporting.
    4. MITRE ATT&CK, Group profile: APT28 (G0007).
    5. FireEye, “APT28: A Window into Russia’s Cyber Espionage Operations?” (2014).
    6. German federal cybersecurity authorities regarding the 2015 Bundestag breach.
    7. U.S. DOJ indictment (2018) and Mueller Report findings.
    8. DOJ charges regarding WADA, USADA, and the Spiez laboratory (2018).
    9. NSA, CISA, FBI, NCSC, “Russian GRU Global Brute Force Campaign” (July 2021).
    10. CERT-UA (UAC-0001) advisories regarding 2022–2025 operations.
    11. CISA and 11-nation joint advisory on Western Logistics targeting (May 2025).
    12. The Hacker News / Akamai reporting on PRISMEX malware (2026).
    13. Trellix Research on January 2026 spear-phishing campaigns.

    External links [edit]

    Categories: Advanced persistent threats · Russian state-sponsored hacking · GRU · Cyberwarfare · Hacking in the 2010s
    This page was last synced August 2026. Content is summarized from public threat intelligence research.