Home/Threat Actor/APT28
Threat Actor

APT28

apt28_fancybear · russia · active since 2004

APT28 (GRU Unit 26165 / Fancy Bear / Forest Blizzard) is a Russian military-intelligence cyber-espionage actor active since 2004 targeting governments, defense, political organizations, anti-doping bodies, and chemical-weapons oversight across NATO states and Ukraine.

documented operations include the 2016 DNC compromise, the WADA and OPCW operations, the LoJax UEFI rootkit, the Drovorub Linux malware family, the Kubernetes-driven Global Brute Force Campaign, and the 2022-2024 Nearest Neighbor Wi-Fi pivot technique.

russia confidence: high 23 aliases MITRE ATT&CK G0007 ↗

Profile

APT28 is a Russian military-intelligence threat actor attributed to the GRU's 85th Main Special Service Center (GTsSS), Unit 26165. Active since at least 2004, it is one of the most thoroughly documented state-sponsored intrusion sets in public reporting and one of only two actors (alongside Sandworm / Unit 74455) to have had identified officers indicted by the US Department of Justice. The group conducts persistent espionage against NATO governments, defense industries, political organizations, anti-doping bodies, chemical-weapons oversight bodies, journalists, dissidents, and Ukrainian targets.

It also engages in influence operations and occasional destructive activity (TV5 Monde 2015). Tradecraft blends spearphishing, password-spray and brute-force at scale (operated from a Kubernetes cluster), credential theft via OAuth abuse, custom implants (X-Agent / CHOPSTICK, Zebrocy, Cannon, ADVSTORESHELL, Drovorub for Linux), and rare-in-the-wild firmware persistence (LoJax UEFI rootkit). In 2022-2024 the group pioneered the "Nearest Neighbor" technique, compromising organizations physically adjacent to the real target, then pivoting via enterprise Wi-Fi.

Aliases

23
apt28fancy bearsofacysednitstrontiumforest blizzardpawn stormiron twilightsnakemackerelswallowtailgroup 74tsar teamthreat group-4127tg-4127frozenlakegruesomelarchapt 28apt-28fancybearg0007sofacy groupsednit groupsofacy apt

Notable Campaigns

11
2024DOJ Indictment of GRU Officers (October 2024)
2022-2024Nearest Neighbor Campaign (C0051)
2020Drovorub Linux Malware Disclosure
2019-2021Global Brute-Force Campaign (Kubernetes)
2019Ukraine Election Interference
2018OPCW Close-Access Operation
2018LoJax UEFI Rootkit Discovery
20162016 DNC and DCCC Compromise
2016World Anti-Doping Agency Breach
2015German Bundestag Hack
2015TV5 Monde Sabotage

Attribution & Reporting

Attributed by
CISANSAFBIUS Department of JusticeUK NCSCMicrosoftMandiantCrowdStrikeFireEyeSecureworksESETTrend MicroKasperskyPalo Alto Networks Unit 42SymantecTalosVolexityGoogle TAG
Key reporting
reportFireEye iSIGHT Intelligence: APT28, At the Center of the Storm (2017)
reportMandiant: APT28, A Window Into Russia's Cyber Espionage Operations (2014)
reportCrowdStrike: Bears in the Midst, Intrusion into the Democratic National Committee (2016)
reportUS DOJ Indictment 1:18-cr-00215, Twelve Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election (2018)
reportNSA/FBI Joint Advisory: Drovorub Russian GRU Malware (August 2020)
reportNSA/FBI/CISA/NCSC Joint Advisory: Russian GRU Global Brute Force Campaign (July 2021)
reportESET: LoJax, First UEFI Rootkit Found in the Wild (September 2018)
reportESET: En Route with Sednit (Parts 1, 2, 3), Multi-part ESET research series (2016)
reportMicrosoft Threat Intelligence: STRONTIUM, Credential Harvesting (September 2020)
reportVolexity: The Nearest Neighbor Attack, Russian APT Weaponizes Nearby Wi-Fi Networks (November 2024)
reportBitdefender: In-depth Analysis of APT28, The Political Cyber-Espionage
reportSecureworks: Threat Group-4127 Targets Hillary Clinton Presidential Campaign
reportTrend Micro: Pawn Storm, Lack of Sophistication as a Strategy (2020)
reportGoogle TAG: Ukraine Remains Russia's Biggest Cyber Focus in 2023
reportEuRepoC: APT Profile, APT 28 (European Repository of Cyber Incidents)

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)47/60 · 78%
Analytics (MITRE CAR)24/60 · 40%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin