Also known as: APT28, tracked as, Pawn Storm, Fancy Bear, Sednit, SNAKEMACKEREL, TsarTeam, TG-4127, STRONTIUM, Swallowtail, IRON TWILIGHT, Group 74, SIG40, Grizzly Steppe, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, Zebocracy, including reconnaissance, taking screenshots, executing files, control infrastructure u, APT29, Sofacy, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER
GreedyBear has operated since 2008 and is widely associated with the Russian GRU’s Fancy Bear operations (APT28). Their most recent campaign involved over 150 malicious Firefox extensions that employ extension hollowing techniques to replace legitimate wallet add‑ons, thereby harvesting users’ cryptocurrency credentials. In addition to browser-based threats, they distributed nearly 500 malicious executables and coordinated multiple simultaneous campaigns across government, defense, financial services, media, energy, pharmaceutical, manufacturing, aerospace, non‑profit, aviation, chemical, nuclear and critical‑infrastructure sectors. The attacker’s toolset combines legacy tools such as XAgent, X‑Tunnel, WinIDS, Foozer and DownRange with newer payloads like CredoMap (a credential stealer) and Havex RAT. GreedyBear also injects malicious PowerShell code disguised as Windows updates to maintain persistence and evade detection. Their supply‑chain compromise strategy leverages CVE‑2022‑30190 (Follina) and the recently disclosed Outlook zero‑day (CVE‑2023‑23397) to gain initial access via spearphishing attachments. Operatively, GreedyBear runs a centralized command‑and‑control network where malicious domains resolve to a single IP address, enabling real‑time exfiltration over standard C2 protocols. They use dynamic code injection and continuous malware updates powered by AI‑generated scripts, ensuring rapid adaptability and resistance to signature‑based defenses.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GreedyBear, also known as APT28/Fancy Bear, is a sophisticated threat actor combining financial theft with espionage objectives. Their latest campaign centered on hijacked Firefox extensions and malicious executables that captured cryptocurrency wallet credentials and stolen more than $1 million in crypto. The operation uses supply‑chain compromise, obfuscation, and centralized C2 infrastructure, expanding to multiple browsers and leveraging AI‑generated code for stealth.
Goals & Targeting
GreedyBear’s strategic objectives blend monetary gain with broader intelligence collection. While the primary motivation appears financial—evidenced by large sums of cryptocurrency stolen—they also target state actors, defense contractors, media outlets, and critical infrastructure across Ukraine, NATO members and European states. The dual focus allows them to collect sensitive data for geopolitical leverage while monetizing compromised accounts through wallet credential theft.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since 2008, GreedyBear has executed large‑scale, multi‑phase campaigns against government and critical infrastructure worldwide. The operator typically launches simultaneous attacks across multiple vectors—phishing, malicious browser extensions, credential stealers, and supply‑chain exploits—maintaining a centralized C2 network that simplifies exfiltration and rapid update of payloads. Their past operations include phishing lures exploiting the Follina vulnerability to deliver CredoMap, an Outlook zero‑day in December 2023 against European government networks, and earlier intrusions into the German Bundestag (2015) and France’s TV5 Monde (2015). The actor consistently targets defense, aerospace, media, energy, pharmaceutical and financial sectors, prioritizing high‑value accounts to facilitate both intelligence gathering and illicit cryptocurrency transactions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on publicly available reports and known indicators shared by security vendors, yielding high confidence in the actor’s capabilities and techniques related to malicious extensions, phishing, and credential theft. However, attribution remains partially ambiguous due to overlapping aliases (APT28/Fancy Bear). Information gaps exist regarding precise timelines for recent operations, the full extent of autonomous vs. state‑directed activities, and detailed infrastructure mapping beyond central C2 addresses. Continuous monitoring is required to confirm any changes in tactics or new exploit vectors.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
11
Techniques
64
Tools
7
Campaigns
37
IOCs
0
Observed Data
7
Tactics