Also known as: APT28, Fancy Bear, tracked as, Midnight Blizzard has, conference Wi-Fi portals worldwide, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, BokBot, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin
UNK_RemoteRogue employs an evolutionarily layered attack chain that begins with spear‑phishing emails bearing malicious attachments or links. By spoofing legitimate company domains, the actor bypasses email security controls and delivers PowerShell scripts or WMI commands to establish persistence via scheduled tasks or autostart mechanisms. Once inside, it exploits well‑known CVEs in webmail platforms—including XSS weaknesses in MDaemon, Horde, Zimbra, Roundcube, and WebDAV flaws (CVE‑2012‑0158, CVE‑2025‑33053)—to inject JavaScript payloads that harvest credentials, emails and contact lists. After initial access, the attacker deploys a suite of RATs such as DarkGate, BrockenDoor, Remcos, Havoc, HanifNet, HXLibrary, and NeoExpressRAT. These backdoors provide remote command execution, credential dumping with Mimikatz, and facilitate lateral movement using legitimate tunneling utilities like plink and Ngrok. Persistence is further hardened via scheduled tasks and autostart entries (e.g., through T1047 WMI or T1547 boot‑logon scripts). The actor also routinely utilizes the SDelete utility to cleanse backups, enabling ransomware deployments such as Babuk in campaigns demanding extortion. UNK_RemoteRogue’s operational tempo shows a pattern of multi‑month campaigns with periodic updates to exploitation tools. Their global attack footprint spans high‑value sectors—including financial services, defense, telecommunications, energy, healthcare and critical infrastructure—in dozens of countries across Eurasia, the Middle East and North America.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNK_RemoteRogue is a state‑level threat actor believed to originate from Russia that blends traditional phishing with sophisticated webmail exploitation and the use of legitimate tunneling tools for lateral movement. The group routinely leverages publicly available WebDAV, Office, and XSS vulnerabilities in front‑end mail clients to deploy JavaScript backdoors, then pivots through RDP, SSH or VPN portals while installing RATs such as DarkGate, BrockenDoor or Remcos. Recent campaigns have additionally incorporated ransomware delivery (Babuk) and click‑based phishing via ClickFix, targeting a broad range of sectors and countries worldwide.
Goals & Targeting
The actor’s strategic objectives appear to be a mix of espionage, sabotage and financial gain. By compromising privileged accounts through stolen VPN credentials or credential dumping, RemoteRogue seeks direct access to classified or proprietary data within targeted organizations. The deployment of ransomware suggests monetization as an additional motive once the actor perceives an opportunity for high‑value ransom payouts. Operationally, the group selects victims that provide either actionable intelligence (e.g., defense contractors, telecom operators) or sizable financial influence, reflecting a dual use of espionage and extortion to advance national strategic interests.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNK_RemoteRogue typically launches multi‑month, phased campaigns that begin with globally distributed spear‑phishing messages and pivot through exploitation of webmail XSS or CVE vulnerabilities. The actor has demonstrated a preference for targeting mid‑level to senior‑tier employees in industries such as defense, telecom, finance and critical infrastructure. In addition to exfiltration and espionage, the group occasionally leverages ransomware (Babuk) when backups are corrupted by SDelete, creating both financial leverage and operational disruption. The operational tempo appears cyclical with periods of quiet intermission between waves; however, recent observations confirm renewed activity in 2024–25, including documented ClickFix usage against a broad developer community.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on multiple independent publications, publicly disclosed threat reports and known tool footprints. High confidence exists regarding the use of phishing, webmail exploitation through XSS/CVE avenues, deployment of RATs (DarkGate, BrockenDoor, Remcos), and ClickFix‑based delivery. However, attribution gaps remain in precise campaign dates, full attack timelines, and the extent of ransomware usage outside a few documented incidents. Continuous monitoring is needed to validate ongoing activity and assess shifts in tactics.
No campaigns linked yet.
No observed data linked yet.
46
Techniques
61
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics