Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Swan Vector

Also known as: Fancy Bear, Cozy Bear, APT28, The Dukes, Sofacy, BlueBravo, APT29, Forest Blizzard, Cloaked Ursa, BlueDelta, FROZENLAKE, Carderbee, CVE-2023-38035, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, Daggerfly, Bronze Highland, China, India, Nobelium, Evasive Panda, LAUNDRY BEAR, SkyCloak, Ethereal Panda, Storm-0401, Rezet, Head Mare, Unicorn, Bronze Elgin, StormBamboo, Midnight Blizzard, SeedWorm, TEMP.Zagros, Static Kitten, APT-C-35, Origami Elephant, APT-C-36, APT43, Emerald Sleet, Sparkling Pisces, Springtail, TA427, Velvet Chollima, APT42, NiceCurl, TameCat, to infiltrate Windows machines, such as VPN services, compromised EdgeOS routers, to hide its tracks, carry out sophisticated attacks, Muddywater, APT36, Linux, Android systems, keygroup777, FamousSparrow, government, engineering, legal sectors, CVE-2023-41183

Description

Swan Vector, an alias that overlaps with other Russian APT groups such as Fancy Bear and Cozy Bear, has been active against a broad spectrum of sectors—financial services, energy, manufacturing, healthcare, logistics and critical infrastructure—in countries across Europe, Asia, the Middle East and the United States. The threat actor employs a blend of spear‑phishing emails bearing malicious attachments (ZIP, LNK, double‑extension files) to inject Cobalt Strike Beacon payloads or enable DLL side‑loading via trusted executables. In addition to these social‑engineering vectors, Swan Vector exploits known client vulnerabilities (CVE‑2017‑11882 Office; CVE‑2024‑11182 webmail; CVE‑2025‑33053 WebDAV) and zero‑days against industrial software such as MDaemon and ViPNet. Once inside the network, the adversary uses living‑off‑the‑land techniques (PowerShell scripts, WMI calls, Windows shell commands) to execute code and establish persistence through startup entries and scheduled tasks. Credential compromise is achieved through legitimate accounts or via custom loaders that inject Mimikatz into memory for credential dumping. The actor also frequently leverages remote monitoring and management tools—Syncro, PDQ—to install backdoors, and employs backup deletion (SDelete) followed by Babuk ransomware to extort victims while ensuring data destruction. The group’s operations are modular: spear‑phishing or webmail XSS drives initial access; DLL side‑loading or exploitation of client CVEs delivers the payload; living‑off‑the‑land tools enable stealthy execution; and RMM/RDP channels are used for lateral movement, privilege escalation, and exfiltration. Swan Vector’s campaigns demonstrate a clear emphasis on maintaining persistence while minimizing detection through sophisticated evasion techniques such as reflective DLL loading and use of legitimate third–party utilities.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Energy
Healthcare
Telecommunications
Education
Critical infrastructure
Manufacturing
Non profit
Media
Hospitality
Retail
Transportation
Aerospace
Nuclear
Utilities
Gaming
Pharmaceutical
Construction
Aviation
Maritime
Legal services
Mining
Think tank
Information technology
Oil gas
Chemical

Targeted Countries / Regions

CN
TW
JP
RU
UA
IR
KR
IN
PL
GB
US
DE
TR
AU
IT
ES
KP
SG
CA
VN
RO
BR
IL
SA
MX
FR
AE
PK
BY
AZ
KZ
EG
NL
NG

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Swan Vector is a high‑sophistication adversary that blends spear‑phishing, zero‑day exploitation and living‑off‑the‑land techniques to compromise industrial and financial targets across Eurasia. The actor leverages legitimate software for DLL side‑loading while deploying Cobalt Strike, Quasar RAT and ShadowPad backdoors. Its campaigns feature both ransomware delivery (Babuk) and data destruction as part of a broader extortion strategy.

Goals & Targeting

Swan Vector seeks financial gain primarily through ransomware extortion, but also obtains espionage data from industrial control systems and critical infrastructure. Its targeting profile focuses on entities that hold large amounts of valuable intellectual property or customer data within the energy, manufacturing, finance, defense and logistics sectors across Eurasia and North America. The actor exploits local knowledge—such as familiarity with corporate domain structures—for domain spoofing and social engineering to increase phishing success rates, while leveraging zero‑days against industry‐specific software to lower barriers to entry.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious attachments (ZIP, LNK, double extensions)
  • DLL side‑loading via trusted executables
  • Phishing emails masquerading as legitimate company or using domain spoofing
  • Exploitation of client vulnerabilities (CVE‑2017‑11882 Office, CVE‑2012‑0158 Office, CVE‑2024‑11182 webmail, CVE‑2025‑33053 WebDAV)
  • Zero‑day attacks on industrial software such as MDaemon and ViPNet
  • Deployment of third‑party RATs (Cobalt Strike Beacon, Quasar RAT, ShadowPad)
  • Living‑off-the‑Land techniques (PowerShell, WMI, Windows shell)
  • Persistence via startup scripts and scheduled tasks
  • Credential compromise and privilege escalation using legitimate accounts
  • Remote exploitation via RDP/SSH/VPN
  • Data destruction of backups with SDelete
  • Deployment of Babuk ransomware for extortion
  • Use of RMM tools (Syncro, PDQ) to deploy payloads
  • Reflective DLL injection/loading backdoors into memory
  • Credential dumping via Mimikatz loaded through custom loaders

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Impact
Exfiltration
Credential Access

ATT&CK Techniques

T1566.001
T1218.014
T1547.009
T1203
T1059.003
T1047
T1053.005
T1078
T1021.001
T1021.002
T1485
T1486
T1059.007
T1190
T1055.005
T1003

Software / Tooling

Cobalt Strike
Quasar RAT
ShadowPad
DarkGate
BrockenDoor
Remcos
Babuk
SynChro
PDQ
Mimikatz
XRed
PlugX
Silent Werewolf
SpyPress.HORDE
SpyPress.MDAEMON
SpyPress.ROUNDCUBE
SpyPress.ZIMBRA
Elise (Trensil)
Horus Agent
Apollo
iediagcmd.exe
Custom reflective injector

Campaigns & Victims

Swan Vector’s campaigns exhibit a modular, high‑tempo approach where initial exploitation is often spear‑phishing or zero‑day delivery followed by rapid lateral movement and persistence establishment. Victims in the energy, manufacturing and financial sectors frequently experience data exfiltration coupled with ransomware demands for Babuk, while backup deletion events provide additional leverage. The group’s pattern of using RMM tools and PowerShell to bypass security controls indicates a preference for tool obfuscation and living‑off‑the‑land tactics. Historical operations reveal a consistent geographic focus on Eurasian nations and their neighboring regions, with occasional incursions into the United States and China through similar vectors.

IOC Patterns

  • ZIP/LNK attachments with double extensions
  • DLL side-loading via legit executable
  • Spoofed domains mimicking legitimate sites
  • Cobalt Strike Beacon binary presence
  • RMM installer download URLs (Syncro/PDQ)
  • Reflective DLL injection payloads
  • Credential dumping artifacts via Mimikatz

Recommended Actions

  • Deploy email filtering and attachment sandboxing for ZIP/LNK files, especially double‑extension variants.
  • Block or monitor suspicious DLL side‑loading events on endpoints.
  • Patch promptly the Office CVEs (CVE‑2017‑11882, CVE‑2012‑0158) and WebDAV CVE‑2025‑33053.
  • Use threat intelligence feeds to block spoofed phishing domains and legitimate company names used in spear‑phishing.
  • Implement EDR/ATP solutions with signatures for Cobalt Strike Beacon and reflective DLL injection patterns.
  • Enforce multi‑factor authentication on privileged accounts to mitigate credential compromise.
  • Restrict or log non‑essential PowerShell, WMI, and Windows shell usage.
  • Detect and alert on scheduled task creation by unknown processes.
  • Maintain offline backups and monitor for SDelete backup deletion activity.
  • Separate ransomware defenses, ensure backups are isolated and hardened.
  • Filter installation of RMM tools (Syncro, PDQ) from untrusted sources.
  • Add detection rules for custom loaders that inject Mimikatz or other backdoors into memory.
  • Apply least‑privilege principles to reduce account exposure.

Suggested Tags

Spear Phishing
DLL Side Loading
Zero-Day Exploit
CVE-2017-11882
Office Exploit
Malicious Attachments
Phantom Domains
Cobalt Strike
Industrial Targeting
backdoors
ransomware
webmail-XSS
WebDAV-exploitation
scheduled-task-persistence
credential-compromise
data-destruction
APT28
BO-Team
RMM exploit
process-injection
credential-dumping
Iran-aligned
MuddyWater
Lyceum
OilRig
Israel-industry-targeting

Confidence Assessment

The information pool is moderate to high confidence for the identified tactics, techniques and tools based on publicly cited advisories and threat research. Attribution remains noisy due to overlapping aliases (Swan Vector/Apt28/Cozy Bear). Gaps persist around the precise operational timeline, full geographic footprint beyond Eurasia, and the extent of zero‑day exploitation versus known CVEs, requiring continuous feed updates.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Fancy Bear
  2. library.bsafes.com — Cited by web research for: Cozy Bear
  3. www.varutra.com — Cited by web research for: npm packages
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.shadowpad — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.quasar_rat — Cited by AI analysis.

Intel Summary

16

Techniques

61

Tools

0

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
espionage
education-sector
Spear Phishing
DLL Side Loading
Zero-Day Exploit
CVE-2017-11882
Office Exploit
Malicious Attachments
Phantom Domains
Cobalt Strike
Industrial Targeting
backdoors
ransomware
webmail-XSS
WebDAV-exploitation
scheduled-task-persistence
credential-compromise
data-destruction
APT28
BO-Team
RMM exploit
process-injection
credential-dumping
Iran-aligned
MuddyWater
Lyceum
OilRig
Israel-industry-targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.