APT28 is a Russian state-sponsored cyber espionage threat actor widely linked to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), commonly associated with Unit 26165. It is one of the most broadly tracked Russian intrusion sets and is widely known under aliases including Fancy Bear, Sofacy, Sednit, Pawn Storm, STRONTIUM, Forest Blizzard, Tsar Team, Swallowtail, Group 74, TG-4127, BlueDelta, UAC-0001, and UAC-0028. Reporting has consistently associated the group with long-running espionage and influence-supporting operations against government, military, diplomatic, political, investigative, and strategic-sector targets, with a particularly strong focus on Ukraine and other geopolitically relevant regions. APT28 is known for credential theft, spearphishing, exploitation of public-facing applications, and webmail-focused intrusion activity. The group has repeatedly targeted email and collaboration platforms, including Zimbra and Roundcube, to steal credentials, session material, mailbox contents, and other sensitive communications. It has also been linked to campaigns against political organizations, the Bundestag, MH17-related entities, the OPCW, and Ukrainian government bodies. In addition to direct exploitation of enterprise software, the group has been tied to operations abusing edge infrastructure such as small-office and home-office routers to gain footholds, redirect authentication traffic, and harvest cloud credentials and OAuth tokens. Its malware and tooling ecosystem includes X-Agent, X-Tunnel, Zebrocy, CHOPSTICK, PixyNetLoader, and LameHug. Recent reporting indicates continued evolution of tradecraft, including COM-based persistence, steganographic payload handling, and use of cloud-backed command-and-control channels. LameHug has been described as incorporating large language model functionality to automate reconnaissance and document collection, reflecting experimentation with AI-enabled operational support. APT28 has also used modules that monitor for USB mass-storage insertion, supporting collection from removable media. Observed tactics and techniques include spearphishing attachments and links, credential harvesting, exploitation of known vulnerabilities, drive-by compromise, persistence via Registry Run keys and Startup-folder mechanisms, removable-media discovery, system information discovery, and covert command-and-control. The group has demonstrated sustained interest in stealthy post-compromise collection, mailbox surveillance, and long-term access to high-value communications. APT28 remains a high-priority Russian military intelligence threat actor with a mature capability set spanning initial access, espionage collection, and infrastructure-enabled follow-on operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
66 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
53 malware families attributed to this actor across reporting.
48 additional families tracked in Mallory.
38 CVEs this actor has used in observed campaigns. 38 of them exploited in the wild.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
Leveraging a network scan we ran in February 2022, we found the server 45.138.87[.]250 / ceriossl[.]info... mentioned in a Qianxin blogpost describing a campaign abusing CVE-2023-23397 that attributed it to Sednit.
These attacks began with a phishing email, purporting to be from Ukraine's hydro-meteorological center, that contained a weaponized LNK file to exploit another vulnerability, CVE-2026-21513. By chaining CVE-2026-21513 with CVE-2026-21510, the Russian spies bypassed Microsoft security features including Defender SmartScreen and remotely executed malicious code on victims' computers.
GooseEgg weaponises CVE-2022-38028 in the Windows Print Spooler service to obtain SYSTEM-level execution.
33 more CVEs tied to this actor tracked in Mallory.
528 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of a procedure within an explanation of the MITRE ATT&CK framework, specifically using COVID-themed spearphishing attachments with embedded macros.
Conducted espionage-focused operations with evolved loaders, cloud-based C2, steganography, and multiple malware tools against Ukraine-focused targets.
Russian GRU-linked activity exploiting SOHO routers globally, including TP-Link devices, in Operation Masquerade.
Mentioned as the actor behind the separate FrostArmada campaign that infected routers and altered DNS settings to steal Microsoft 365 credentials and OAuth tokens.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.