Skip to main content
Mallory
Groups In DevelopmentRussia🇷🇺 RU49 malware familiesExploits CVEs in the wild

APT28

Also known asAPT28APT28 (Fancy Bear)APT28 (Forest Blizzard)APT28 (Forest/Forrest Blizzard)APT28 (WinRAR usage in campaign)APT28 Nearest Neighbor CampaignATG2atk5Blue AthenaBlue KitsuneBlueBravobluedeltaCrisisFourfancy_bearfancy_bearsfancybearfighting_ursaForest BlizzardForest Blizzard (STRONTIUM/APT28/Fancy Bear)Forest Blizzard/STRONTIUMFROZENLAKEg0007GRAPHITEGrizzly SteppeGroup 74GruesomeLarchHELLFIREIRON HEMLOCKIron RitualIRON TWILIGHTitg05Operation Pawn StormPawn StormSednitsig40SNAKEMACKERELsofacysofacy_groupSTRONTIUMSwallowtailt_apt_12TG-4127Threat Group-4127Tsar Teamuac_0001uac_0028UAC-0001 (APT28)UAC-0028 (APT28)YttriumZ-Lom Team

APT28 is a Russian state-sponsored intrusion set publicly attributed to the GRU’s Unit 26165 and widely tracked under aliases including Fancy Bear, Forest Blizzard, Sofacy, Sednit, Pawn Storm, Strontium, Fighting Ursa, BlueDelta, UAC-0001, and UAC-0028. The group has conducted cyber espionage, credential theft, and influence or hack-and-leak operations for roughly two decades, primarily targeting government, defense, diplomatic, military, critical infrastructure, logistics, transportation, and policy organizations, with a strong focus on NATO member states, Ukraine, Europe, and the United States. The content describes APT28 as one of the most prolific and persistent GRU-linked actors. Reported historic operations include the 2015 German Bundestag intrusion, the TV5Monde sabotage operation conducted under the fake CyberCaliphate persona, the 2016 intrusions into the DCCC, DNC, and Hillary Clinton campaign, and the leak of stolen World Anti-Doping Agency athlete medical records during the 2016 Rio Olympics. The group also used fake personas under the DC Leaks banner to seed stolen information to journalists. APT28 has used spear phishing, exploit delivery, credential harvesting, webmail theft, and edge-device compromise. The content states it exploited CVE-2023-23397 to harvest Net-NTLMv2 hashes from European government, military, energy, and transportation targets, and weaponized CVE-2026-21509 within 24 hours of disclosure in a January 2026 espionage campaign against European military, government, maritime, and transport organizations. That campaign used malicious Office documents with embedded OLE objects and WebDAV-delivered payloads, first-stage loaders including SimpleLoader or SimpleDropper, COM hijacking persistence, and either a steganography-based loader that extracted an in-memory Covenant Grunt implant from PNG files or an Outlook VBA backdoor called NotDoor for long-term mailbox collection and forwarding. The group’s malware and tooling in the content include Seduploader, X-Agent, X-Tunnel, Sedreco, Zebrocy, GooseEgg, HeadLace, CredoMap, MASEPIE, OCEANMAP, STEELHOOK, BeardShell, Slimagent, LameHug, PixyNetLoader, Jaguar Tooth, Covenant/Covenant Grunt, and NotDoor. PixyNetLoader is described as a DLL-based loader active since late 2024 that hides encrypted payloads in PNG image files using steganography and executes a Covenant Grunt implant in memory, with command and control via the FILEN cloud service. ESET reported APT28 using BeardShell and Covenant since April 2024 for long-term surveillance of Ukrainian military personnel, drone manufacturers, and drone research and development organizations, while also targeting logistics and transportation companies outside Ukraine. The content also highlights APT28’s infrastructure shift from rented VPS systems to compromised SOHO and edge devices, including Ubiquiti EdgeRouters, MikroTik, TP-Link, and older Cisco IOS routers. Reported operations include use of a MooBot-based router botnet later disrupted by the FBI’s Operation Dying Ember, the FrostArmada campaign that rewrote DNS settings for adversary-in-the-middle credential and OAuth token theft, and deployment of the custom Cisco IOS malware Jaguar Tooth via CVE-2017-6742 after identifying weak SNMP community strings. The group has also abused legitimate cloud services such as Koofr, Icedrive, and Filen for covert command and control. Victimology in the content includes Ukrainian government and defense targets, Ukrainian military personnel, European foreign ministries, law enforcement, maritime and transport organizations, democratic think tanks, intelligence targets, international sporting organizations, and Western or NATO-country logistics providers, tech companies, and government organizations supporting Ukraine. The content also notes use of targeted lure material for credential harvesting and modules that notify operators when USB mass storage devices are inserted. APT28 is additionally described as using PowerShell, staging captured credentials in files such as pi.log and in C:\ProgramData, and deploying malware that copied itself to the Startup directory for persistence.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military
  • Utilities
  • Transportation
  • Software & Services
  • Academia & Research

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine
  • 🇺🇸 United States
  • 🇩🇪 Germany
  • 🇫🇷 France
  • 🇵🇱 Poland
  • 🇧🇬 Bulgaria
  • 🇷🇴 Romania

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

66 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics102 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0042
Resource Development
3 techniques
T1583
Acquire Infrastructure
T1583.001
Domains
T1583.007×2
Serverless
T1584
Compromise Infrastructure
T1584.008×2
Network Devices
T1585
Establish Accounts
T1585.001
Social Media Accounts
TA0001
Initial Access
5 techniques
T1078
Valid Accounts
T1189
Drive-by Compromise
T1190
Exploit Public-Facing Application
T1199
Trusted Relationship
T1566×4
Phishing
T1566.001×3
Spearphishing Attachment
T1566.002×2
Spearphishing Link
TA0002
Execution
4 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003×4
Windows Command Shell
T1059.005×2
Visual Basic
T1059.007
JavaScript
T1203×3
Exploitation for Client Execution
T1204
User Execution
T1204.002×3
Malicious File
TA0003
Persistence
7 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1078
Valid Accounts
T1137
Office Application Startup
T1137.001
Office Template Macros
T1543
Create or Modify System Process
T1543.001
Launch Agent
T1546
Event Triggered Execution
T1546.015×2
Component Object Model Hijacking
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
T1556
Modify Authentication Process
TA0004
Privilege Escalation
7 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1055
Process Injection
T1068×2
Exploitation for Privilege Escalation
T1078
Valid Accounts
T1543
Create or Modify System Process
T1543.001
Launch Agent
T1546
Event Triggered Execution
T1546.015×2
Component Object Model Hijacking
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0005
Stealth
8 techniques
T1027
Obfuscated Files or Information
T1027.003
Steganography
T1055
Process Injection
T1070
Indicator Removal
T1070.004
File Deletion
T1078
Valid Accounts
T1140×2
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.011
Rundll32
T1497
Virtualization/Sandbox Evasion
T1497.003
Time Based Checks
T1620
Reflective Code Loading
TA0112
Defense Impairment
1 technique
T1556
Modify Authentication Process
TA0006
Credential Access
7 techniques
T1003×2
OS Credential Dumping
T1056
Input Capture
T1056.001×2
Keylogging
T1110
Brute Force
T1110.003
Password Spraying
T1528
Steal Application Access Token
T1556
Modify Authentication Process
T1557×2
Adversary-in-the-Middle
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
3 techniques
T1057
Process Discovery
T1082
System Information Discovery
T1497
Virtualization/Sandbox Evasion
T1497.003
Time Based Checks
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
7 techniques
T1056
Input Capture
T1056.001×2
Keylogging
T1074×3
Data Staged
T1113
Screen Capture
T1114
Email Collection
T1185
Browser Session Hijacking
T1557×2
Adversary-in-the-Middle
T1560×2
Archive Collected Data
TA0011
Command and Control
6 techniques
T1071×3
Application Layer Protocol
T1071.001×2
Web Protocols
T1071.002
File Transfer Protocols
T1071.003
Mail Protocols
T1090
Proxy
T1090.003×2
Multi-hop Proxy
T1102
Web Service
T1105×3
Ingress Tool Transfer
T1568
Dynamic Resolution
T1573
Encrypted Channel
T1573.001
Symmetric Cryptography
TA0010
Exfiltration
4 techniques
T1020
Automated Exfiltration
T1041×2
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1567
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
2 techniques
T1498
Network Denial of Service
T1565
Data Manipulation
T1565.001
Stored Data Manipulation
WEAPONIZED

Associated vulnerabilities

29 CVEs this actor has used in observed campaigns. 29 of them exploited in the wild.

CVE-2026-21509Microsoft Office OLE/Shell.Explorer.1 Security Feature BypassIn the wildEvidence18

PixyNetLoader is a DLL-based malware loader. It arrives via a malicious Office document that exploits CVE-2026-21509.

CVE-2026-21513MSHTML Framework Security Feature Bypass in Internet Explorer/MSHTMLIn the wildEvidence14

These attacks began with a phishing email, purporting to be from Ukraine's hydro-meteorological center, that contained a weaponized LNK file to exploit another vulnerability, CVE-2026-21513. By chaining CVE-2026-21513 with CVE-2026-21510, the Russian spies bypassed Microsoft security features including Defender SmartScreen and remotely executed malicious code on victims' computers.

CVE-2026-21510Windows Shell SmartScreen and Security Prompt Bypass via Malicious LNK/LinkIn the wildEvidence10

CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.

CVE-2023-50224Authentication Bypass Information Disclosure in TP-Link TL-WR841N httpdIn the wildEvidence9

The FBI on Tuesday warned that Russia's GRU, via Fancy Bear, has been exploiting routers to steal credentials from organizations worldwide. The agency singled out TP-Link routers compromised via CVE-2023-50224.

CVE-2023-23397Microsoft Outlook Net-NTLMv2 Hash Leak via Reminder Sound UNC PathIn the wildEvidence8

APT28 weaponised the zero-click flaw CVE-2023-23397, patched by Microsoft in March 2023 after a CERT-UA report. In-the-wild exploitation ran from April to December 2022 against European government, military, energy and transportation targets.

24 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

359 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

cyber security newsNews
Jun 12, 2026
Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks

Long-running espionage-focused threat actor shifting from traditional VPS infrastructure to compromised SOHO routers, consumer devices, and legitimate cloud services for covert command-and-control, phishing, credential theft, and stealthier cyber operations.

Read more
sekoia blogNews
Jun 11, 2026
APT28, an evolution of tradecraft - Sekoia.io Blog

Long-running Russian military intelligence espionage and influence actor targeting government, defense, diplomatic, critical infrastructure, civil society, and military entities. The content describes evolution from X-Agent/X-Tunnel-era intrusions and hack-and-leak operations to credential harvesting, Outlook zero-click exploitation, compromised edge-router infrastructure, webmail exploitation, modular implants, and newer cloud-backed and LLM-assisted malware operations focused heavily on Ukraine, NATO members, and Europe.

Read more
recordedfutureNews
Jun 10, 2026
2026 FIFA World Cup: What Public Safety Officials Need to Know

Uses targeted lure material to harvest credentials from intelligence targets; World Cup-related lures could be used for phishing emails, fake login portals, malicious attachments, or impersonation of legitimate event-related services.

Read more
security online infoNews
Jun 8, 2026
PixyNetLoader Malware Analysis: APT28's PNG Trick

Linked to PixyNetLoader campaigns that hide payloads in PNG files using steganography, deliver via malicious Office documents exploiting CVE-2026-21509, establish COM persistence, extract and execute Covenant Grunt in memory, and use the FILEN cloud service for command and control. Exatrack also identified APT28 tools SlimAgent and Graphite through shared binary packaging characteristics.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping66

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal49

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs29

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables359

Domains, IPs, and hashes tied to this actor, refreshed continuously.