Also known as: Fancy Bear, Cozy Bear, APT28, The Dukes, Sofacy, BlueBravo, APT29, Forest Blizzard, Cloaked Ursa, BlueDelta, FROZENLAKE, Carderbee, CVE-2023-38035, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, Daggerfly, Bronze Highland, China, India, Nobelium, Evasive Panda, LAUNDRY BEAR, SkyCloak, Ethereal Panda, Storm-0401, Rezet, Head Mare, Unicorn, Bronze Elgin, StormBamboo, Midnight Blizzard, SeedWorm, TEMP.Zagros, Static Kitten, APT-C-35, Origami Elephant, APT-C-36, APT43, Emerald Sleet, Sparkling Pisces, Springtail, TA427, Velvet Chollima, APT42, NiceCurl, TameCat, to infiltrate Windows machines, such as VPN services, compromised EdgeOS routers, to hide its tracks, carry out sophisticated attacks, Muddywater, APT36, Linux, Android systems, keygroup777, FamousSparrow, government, engineering, legal sectors, CVE-2023-41183
Swan Vector, an alias that overlaps with other Russian APT groups such as Fancy Bear and Cozy Bear, has been active against a broad spectrum of sectors—financial services, energy, manufacturing, healthcare, logistics and critical infrastructure—in countries across Europe, Asia, the Middle East and the United States. The threat actor employs a blend of spear‑phishing emails bearing malicious attachments (ZIP, LNK, double‑extension files) to inject Cobalt Strike Beacon payloads or enable DLL side‑loading via trusted executables. In addition to these social‑engineering vectors, Swan Vector exploits known client vulnerabilities (CVE‑2017‑11882 Office; CVE‑2024‑11182 webmail; CVE‑2025‑33053 WebDAV) and zero‑days against industrial software such as MDaemon and ViPNet. Once inside the network, the adversary uses living‑off‑the‑land techniques (PowerShell scripts, WMI calls, Windows shell commands) to execute code and establish persistence through startup entries and scheduled tasks. Credential compromise is achieved through legitimate accounts or via custom loaders that inject Mimikatz into memory for credential dumping. The actor also frequently leverages remote monitoring and management tools—Syncro, PDQ—to install backdoors, and employs backup deletion (SDelete) followed by Babuk ransomware to extort victims while ensuring data destruction. The group’s operations are modular: spear‑phishing or webmail XSS drives initial access; DLL side‑loading or exploitation of client CVEs delivers the payload; living‑off‑the‑land tools enable stealthy execution; and RMM/RDP channels are used for lateral movement, privilege escalation, and exfiltration. Swan Vector’s campaigns demonstrate a clear emphasis on maintaining persistence while minimizing detection through sophisticated evasion techniques such as reflective DLL loading and use of legitimate third–party utilities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Swan Vector is a high‑sophistication adversary that blends spear‑phishing, zero‑day exploitation and living‑off‑the‑land techniques to compromise industrial and financial targets across Eurasia. The actor leverages legitimate software for DLL side‑loading while deploying Cobalt Strike, Quasar RAT and ShadowPad backdoors. Its campaigns feature both ransomware delivery (Babuk) and data destruction as part of a broader extortion strategy.
Goals & Targeting
Swan Vector seeks financial gain primarily through ransomware extortion, but also obtains espionage data from industrial control systems and critical infrastructure. Its targeting profile focuses on entities that hold large amounts of valuable intellectual property or customer data within the energy, manufacturing, finance, defense and logistics sectors across Eurasia and North America. The actor exploits local knowledge—such as familiarity with corporate domain structures—for domain spoofing and social engineering to increase phishing success rates, while leveraging zero‑days against industry‐specific software to lower barriers to entry.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Swan Vector’s campaigns exhibit a modular, high‑tempo approach where initial exploitation is often spear‑phishing or zero‑day delivery followed by rapid lateral movement and persistence establishment. Victims in the energy, manufacturing and financial sectors frequently experience data exfiltration coupled with ransomware demands for Babuk, while backup deletion events provide additional leverage. The group’s pattern of using RMM tools and PowerShell to bypass security controls indicates a preference for tool obfuscation and living‑off‑the‑land tactics. Historical operations reveal a consistent geographic focus on Eurasian nations and their neighboring regions, with occasional incursions into the United States and China through similar vectors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information pool is moderate to high confidence for the identified tactics, techniques and tools based on publicly cited advisories and threat research. Attribution remains noisy due to overlapping aliases (Swan Vector/Apt28/Cozy Bear). Gaps persist around the precise operational timeline, full geographic footprint beyond Eurasia, and the extent of zero‑day exploitation versus known CVEs, requiring continuous feed updates.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
61
Tools
0
Campaigns
40
IOCs
0
Observed Data
7
Tactics