FORENSIA

THREAT_ACTOR · G0007

APT28

Also known as: APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch

Profile

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

MITRE ATT&CK ↗

Techniques

93 ATT&CK techniques attributed to this actor.

T1001.001 Junk DataT1003 OS Credential DumpingT1003.001 LSASS MemoryT1003.003 NTDST1005 Data from Local SystemT1014 RootkitT1021.002 SMB/Windows Admin SharesT1025 Data from Removable MediaT1027.013 Encrypted/Encoded FileT1030 Data Transfer Size LimitsT1036 MasqueradingT1036.005 Match Legitimate Resource Name or LocationT1037.001 Logon Script (Windows)T1039 Data from Network Shared DriveT1040 Network SniffingT1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1056.001 KeyloggingT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1071.003 Mail ProtocolsT1074.001 Local Data StagingT1074.002 Remote Data StagingT1078 Valid AccountsT1078.004 Cloud AccountsT1083 File and Directory DiscoveryT1090.002 External ProxyT1090.003 Multi-hop ProxyT1091 Replication Through Removable MediaT1092 Communication Through Removable MediaT1098.002 Additional Email Delegate PermissionsT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1110 Brute ForceT1110.001 Password GuessingT1110.003 Password SprayingT1113 Screen CaptureT1114.002 Remote Email CollectionT1119 Automated CollectionT1120 Peripheral Device DiscoveryT1133 External Remote ServicesT1134.001 Token Impersonation/TheftT1137.002 Office TestT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1210 Exploitation of Remote ServicesT1211 Exploitation for StealthT1213 Data from Information RepositoriesT1213.002 SharepointT1218.011 Rundll32T1221 Template InjectionT1498 Network Denial of ServiceT1505.003 Web ShellT1528 Steal Application Access TokenT1542.003 BootkitT1546.015 Component Object Model HijackingT1547.001 Registry Run Keys / Startup FolderT1550.001 Application Access TokenT1550.002 Pass the HashT1557.004 Evil TwinT1559.002 Dynamic Data ExchangeT1560 Archive Collected DataT1560.001 Archive via UtilityT1564.001 Hidden Files and DirectoriesT1564.003 Hidden WindowT1566.001 Spearphishing AttachmentT1567 Exfiltration Over Web ServiceT1573.001 Symmetric CryptographyT1583.001 DomainsT1583.003 Virtual Private ServerT1583.006 Web ServicesT1584.008 Network DevicesT1586.002 Email AccountsT1588.002 ToolT1588.007 Artificial IntelligenceT1589.001 CredentialsT1591 Gather Victim Org InformationT1595.002 Vulnerability ScanningT1596 Search Open Technical DatabasesT1598 Phishing for InformationT1598.003 Spearphishing LinkT1669 Wi-Fi NetworksT1684.001 ImpersonationT1685.005 Clear Windows Event Logs

Software

29 malware/tools attributed to this actor.

MimikatzCHOPSTICKNetJHUHUGITADVSTORESHELLXTunnelDowndelphHIDEDRVUSBStealerCORESHELLOLDBAITcertutilXAgentOSXKomplexResponderTorWinexeForfilesDealersChoiceKoadicZebrocyCannonLoJaxFysbisDrovorubWevtutilreGeorgcipher.exeLAMEHUG

Related corpus activity

10,361 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT28.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-11837cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2025-0921cve852
cve-2013-3307cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2025-66478cve852
cve-2026-22584cve852
cve-2021-27076cve851
cve-2025-68670cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2020-22658cve852
cve-2022-47945cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,361.