APT28

MITRE ATT&CK: G0007 View on attack.mitre.org

Aliases: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, FANCY BEAR, SIG40, Grizzly Steppe, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, T-APT-12, APT-C-20, UAC-0028, UAC-0001, BlueDelta, APT28, ATG2, Z-Lom Team, Operation Pawn Storm, CrisisFour, HELLFIRE, APT 28, TsarTeam, Group-4127, Grey-Cloud

First seen
2004-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
expert
Resource level
government
Actor type
Espionage
Related IoCs
5 (1 malicious)
Last IoC activity
2026-08-28 16:38:05
Profile updated
2026-07-30 10:09:24

Targeted industries: defense-and-aerospace education-and-nonprofits energy-and-utilities government-and-public-sector healthcare-and-pharmaceutical media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:us country_code:ua country_code:de country_code:fr country_code:nl country_code:gb country_code:ge country_code:me country_code:mk country_code:cz country_code:pl country_code:no country_code:dk country_code:se country_code:fi country_code:ee country_code:lv country_code:lt country_code:be country_code:ch

Context

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to APT28 (G0007). The 1 most recently updated:

TypeIndicatorUpdatedSources
IP address 151.80.74.167 2026-08-28 4

Detection coverage

  • 27 YARA rules
  • 973 Sigma rules

Malware & tools used

  • Credentials (attack-pattern)
  • Gather Victim Org Information (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Search Open Technical Databases (attack-pattern)
  • Domains (attack-pattern)
  • Timestomp (attack-pattern)
  • External Proxy (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • PowerShell (attack-pattern)
  • Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Email Accounts (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Web Shell (attack-pattern)
  • Network Devices (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Logon Script (Windows) (attack-pattern)
  • Tool (attack-pattern)
  • Hidden Window (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Exfiltration Over Web Service (attack-pattern)
  • Keylogging (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • MITRE ATT&CK — G0007 (report)
  • Wikipedia — Fancy Bear (report)
  • Wikipedia — Sofacy Group (report)
  • bbc.com — Technology 37590375 (report)
  • bbc.co.uk — Technology 45257081 (report)
  • cfr.org — Apt 28 (report)
  • apnews.com — 4D174E45Ef5843A0Ba82E804F080988F (report)
  • voanews.com — 3793874 (report)
  • Kaspersky — 83930 (report)
  • dw.com — A 19564630 (report)
  • Palo Alto Unit 42 — Unit42 Sofacys Komplex Os X Trojan (report)
  • Palo Alto Unit 42 — Dear Joohn Sofacy Groups Global Campaign (report)
  • Mandiant — Probable Apt28 Useo (report)
  • Mandiant — Wp Mandiant Matryoshka Mining (report)
  • eff.org — New Spear Phishing Campaign Pretends Be Eff (report)
  • aptnotes.malwareconfig.com — Viewer (report)
  • accenture.com — Blogs Snakemackerel Delivers Zekapab Malware (report)
  • wired.com — Russian Fancy Bears Hackers Release Apparent Ioc Emails (report)
  • Broadcom/Symantec — Apt28 Espionage Military Government (report)
  • CrowdStrike — Bears Midst Intrusion Democratic National Committee (report)
  • Palo Alto Unit 42 — Unit42 Sofacy Attacks Multiple Government Entities (report)
  • Kaspersky — 72924 (report)
  • msn.com — Ar Bbnv2Ny (report)

Attributed from

  • APT28 Cisco Router Exploits (campaign)
  • APT28 Nearest Neighbor Campaign (campaign)
  • APT28 Router Compromise Attacks (campaign)

External references