Threat actor
APT28
Last fetched
APT28 is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 93 techniques and also known as 30 other names.
Also known as
Pawn Storm, FANCY BEAR, Sednit, SNAKEMACKEREL, Tsar Team, TG-4127, STRONTIUM, Swallowtail, IRON TWILIGHT, Group 74, SIG40, Grizzly Steppe, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, T-APT-12, APT-C-20, UAC-0028, UAC-0001, FROZENLAKE, Sofacy, Forest Blizzard, BlueDelta, Fancy Bear, GruesomeLarch, LAKE RELIC, Threat Group-4127
Description
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).
Techniques by tactic
Collection
- T1005 · Data from Local System
- T1025 · Data from Removable Media
- T1039 · Data from Network Shared Drive
- T1056.001 · Keylogging
- T1074.001 · Local Data Staging
- T1074.002 · Remote Data Staging
- T1113 · Screen Capture
- T1114.002 · Remote Email Collection
- T1119 · Automated Collection
- T1213 · Data from Information Repositories
- T1213.002 · Sharepoint
- T1557.004 · Evil Twin
- T1560 · Archive Collected Data
- T1560.001 · Archive via Utility
Persistence
- T1037.001 · Logon Script (Windows)
- T1078 · Valid Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1133 · External Remote Services
- T1137.002 · Office Test
- T1505.003 · Web Shell
- T1542.003 · Bootkit
- T1546.015 · Component Object Model Hijacking
- T1547.001 · Registry Run Keys / Startup Folder
Privilege Escalation
- T1037.001 · Logon Script (Windows)
- T1068 · Exploitation for Privilege Escalation
- T1078 · Valid Accounts
- T1078.004 · Cloud Accounts
- T1098.002 · Additional Email Delegate Permissions
- T1134.001 · Token Impersonation/Theft
- T1546.015 · Component Object Model Hijacking
- T1547.001 · Registry Run Keys / Startup Folder
Stealth
- T1014 · Rootkit
- T1027.013 · Encrypted/Encoded File
- T1036 · Masquerading
- T1036.005 · Match Legitimate Resource Name or Location
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078 · Valid Accounts
- T1078.004 · Cloud Accounts
- T1134.001 · Token Impersonation/Theft
- T1140 · Deobfuscate/Decode Files or Information
- T1211 · Exploitation for Stealth
- T1218.011 · Rundll32
- T1221 · Template Injection
- T1542.003 · Bootkit
- T1564.001 · Hidden Files and Directories
- T1564.003 · Hidden Window
- T1684.001 · Impersonation
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to APT28 today — this states the absence of a published link, not that APT28 has no infrastructure.
References
- https://attack.mitre.org/groups/G0007/
- https://en.wikipedia.org/wiki/Fancy_Bear
- https://en.wikipedia.org/wiki/Sofacy_Group
- https://www.bbc.com/news/technology-37590375
- https://www.bbc.co.uk/news/technology-45257081
- https://www.cfr.org/interactive/cyber-operations/apt-28
- https://www.apnews.com/4d174e45ef5843a0ba82e804f080988f
- https://www.voanews.com/a/iaaf-hack-fancy-bears/3793874.html
- https://securelist.com/a-slice-of-2017-sofacy-activity/83930/
- https://www.dw.com/en/hackers-lurking-parliamentarians-told/a-19564630
- https://unit42.paloaltonetworks.com/unit42-sofacys-komplex-os-x-trojan/
- https://unit42.paloaltonetworks.com/dear-joohn-sofacy-groups-global-campaign/
- https://www.fireeye.com/blog/threat-research/2015/04/probable_apt28_useo.html
- https://www2.fireeye.com/rs/848-DID-242/images/wp-mandiant-matryoshka-mining.pdf
- https://www.eff.org/deeplinks/2015/08/new-spear-phishing-campaign-pretends-be-eff
- https://aptnotes.malwareconfig.com/web/viewer.html?file=../APTnotes/2014/apt28.pdf
- https://www.accenture.com/us-en/blogs/blogs-snakemackerel-delivers-zekapab-malware
- https://www.wired.com/story/russian-fancy-bears-hackers-release-apparent-ioc-emails/
- https://symantec-blogs.broadcom.com/blogs/election-security/apt28-espionage-military-government
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
- https://unit42.paloaltonetworks.com/unit42-sofacy-attacks-multiple-government-entities/
- https://securelist.com/sofacy-apt-hits-high-profile-targets-with-updated-toolset/72924/
- https://www.msn.com/en-nz/news/world/russian-hackers-accused-of-targeting-un-chemical-weapons-watchdog-mh17-files/ar-BBNV2ny
- https://unit42.paloaltonetworks.com/unit42-new-sofacy-attacks-against-us-government-agency/
- https://unit42.paloaltonetworks.com/unit42-let-ride-sofacy-groups-dealerschoice-attacks-continue/
- https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/
- https://unit42.paloaltonetworks.com/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan/
- https://www.bleepingcomputer.com/news/security/apt28-uses-lojax-first-uefi-rootkit-seen-in-the-wild/
- https://blog.trendmicro.com/trendlabs-security-intelligence/pawn-storm-targets-mh17-investigation-team/
- https://researchcenter.paloaltonetworks.com/2016/06/unit42-new-sofacy-attacks-against-us-government-agency/
- https://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-operation-pawn-storm.pdf
- https://blog.trendmicro.com/trendlabs-security-intelligence/new-adobe-flash-zero-day-used-in-pawn-storm-campaign/
- https://blogs.microsoft.com/on-the-issues/2018/08/20/we-are-taking-new-steps-against-broadening-threats-to-democracy/
- https://www.lse.co.uk/AllNews.asp?code=kwdwehme&headline=Russian_Hackers_Suspected_In_Cyberattack_On_German_Parliament
- https://www.volkskrant.nl/cultuur-media/russen-faalden-bij-hackpogingen-ambtenaren-op-nederlandse-ministeries~b77ff391/
- https://www.ibtimes.co.uk/russian-hackers-fancy-bear-likely-breached-olympic-drug-testing-agency-dnc-experts-say-1577508
- https://www.bleepingcomputer.com/news/security/microsoft-disrupts-apt28-hacking-campaign-aimed-at-us-midterm-elections/
- https://www.justice.gov/opa/pr/justice-department-announces-actions-disrupt-advanced-persistent-threat-28-botnet-infected
- https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf
- https://www.reuters.com/article/us-sweden-doping/swedish-sports-body-says-anti-doping-unit-hit-by-hacking-attack-idUSKCN1IG2GN
- https://researchcenter.paloaltonetworks.com/2016/10/unit42-dealerschoice-sofacys-flash-player-exploit-platform/
- https://netzpolitik.org/2015/digital-attack-on-german-parliament-investigative-report-on-the-hack-of-the-left-party-infrastructure-in-bundestag/
- https://www.washingtonpost.com/technology/2019/02/20/microsoft-says-it-has-found-another-russian-operation-targeting-prominent-think-tanks/?utm_term=.870ff11468ae
- https://www.handelsblatt.com/today/politics/election-risks-russia-linked-hackers-target-german-political-foundations/23569188.html?ticket=ST-2696734-GRHgtQukDIEXeSOwksXO-ap1
- https://www.accenture.com/t20190213T141124Z__w__/us-en/_acnmedia/PDF-94/Accenture-SNAKEMACKEREL-Threat-Campaign-Likely-Targeting-NATO-Members-Defense-and-Military-Outlets.pdf
- https://marcoramilli.com/2019/12/05/apt28-attacks-evolution/
- https://www.microsoft.com/security/blog/2020/09/10/strontium-detecting-new-patters-credential-harvesting/
- https://www.bleepingcomputer.com/news/security/russian-hackers-use-fake-nato-training-docs-to-breach-govt-networks/
- https://quointelligence.eu/2020/09/apt28-zebrocy-malware-campaign-nato-theme/
- https://unit42.paloaltonetworks.com/atoms/fighting-ursa/
- https://blog.google/threat-analysis-group/continued-cyber-activity-in-eastern-europe-observed-by-tag
- https://blog.google/threat-analysis-group/fog-of-war-how-the-ukraine-conflict-transformed-the-cyber-threat-landscape/
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Analysen-und-Prognosen/Threat-Intelligence/Aktive_APT-Gruppen/aktive-apt-gruppen_node.html
- https://bluepurple.binaryfirefly.com/p/bluepurple-pulse-week-ending-june-64e
- https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
- https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/
- https://attack.mitre.org/groups/G0007
- https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf#zoom=50
- https://blog.google/threat-analysis-group/ukraine-remains-russias-biggest-cyber-focus-in-2023/
- https://www.justice.gov/opa/page/file/1098481/download
- https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296A_GRIZZLY%20STEPPE-2016-1229.pdf
- https://www.welivesecurity.com/2019/05/22/journey-zebrocy-land/
- http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part3.pdf
- https://researchcenter.paloaltonetworks.com/2018/03/unit42-sofacy-uses-dealerschoice-target-european-government-agency/
- https://www.mandiant.com/sites/default/files/2021-09/APT28-Center-of-Storm-2017.pdf
- https://web.archive.org/web/20151022204649/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
- https://arstechnica.com/information-technology/2018/07/from-bitly-to-x-agent-how-gru-hackers-targeted-the-2016-presidential-election/
- https://www.trendmicro.com/en_us/research/20/l/pawn-storm-lack-of-sophistication-as-a-strategy.html
- https://researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-attacks/
- https://blog.talosintelligence.com/2017/10/cyber-conflict-decoy-document.html
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://msrc-blog.microsoft.com/2019/08/05/corporate-iot-a-path-to-intrusion/
- https://cdn.cnn.com/cnn/2018/images/07/13/gru.indictment.pdf
- https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF
- https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF
- https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign
- https://www.secureworks.com/research/iron-twilight-supports-active-measures
- https://www.secureworks.com/research/threat-profiles/iron-twilight
- https://www.symantec.com/blogs/election-security/apt28-espionage-military-government
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from APT28 into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.