← All Threat Actors
Threat Actor Profile

APT28

85th Main Special Service Center APT-C-20 ATG2 ATK5 Blue Athena BlueDelta CrisisFour FANCY BEAR Fighting Ursa Forest Blizzard FROZENLAKE G0007 Grey-Cloud Grizzly Steppe Group 74 GruesomeLarch HELLFIRE IRON TWILIGHT ITG05 Pawn Storm Sednit SIG40 SNAKEMACKEREL Sofacy STRONTIUM Swallowtail T-APT-12 TA422 TAG-0700 TG-4127 Threat Group-4127 Tsar Team UAC-0001 UAC-0028 Unit 26165 Z-Lom Team
⚠ Critical Threat
European Political Espionage Campaign, Ukrainian Defense Sector Targeting, NATO Infrastructure Reconnaissance
Origin Russia
Sponsor Russian Federation (GRU)
Motivation Strategic espionage, geopolitical intelligence gathering, and influence operations related to military and political decision-making.

Target Sectors

Governmental Organizations Military and Defense Industrial Base NATO Member States European Union Institutions Ukrainian Government and Critical Infrastructure Diplomatic Entities Media and Think Tanks

Known TTPs

Spear-phishing via highly tailored social engineering
Exploitation of Zero-day vulnerabilities (notably in Microsoft Outlook and Office)
Credential harvesting through sophisticated phishing landing pages
Living-off-the-Land (LotL) using legitimate system tools to evade detection
Exploitation of edge devices (VPNs, routers, and firewalls)
Use of legitimate cloud services (Google Drive, OneDrive) for malware delivery and C2
NTLM relay attacks
Deployment of custom backdoors (e.g., X-Agent, Zebrocy, Sednit)

Related Intelligence


LINK COPIED TO CLIPBOARD