Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GreedyBear

Also known as: APT28, tracked as, Pawn Storm, Fancy Bear, Sednit, SNAKEMACKEREL, TsarTeam, TG-4127, STRONTIUM, Swallowtail, IRON TWILIGHT, Group 74, SIG40, Grizzly Steppe, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, Zebocracy, including reconnaissance, taking screenshots, executing files, control infrastructure u, APT29, Sofacy, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER

Description

GreedyBear has operated since 2008 and is widely associated with the Russian GRU’s Fancy Bear operations (APT28). Their most recent campaign involved over 150 malicious Firefox extensions that employ extension hollowing techniques to replace legitimate wallet add‑ons, thereby harvesting users’ cryptocurrency credentials. In addition to browser-based threats, they distributed nearly 500 malicious executables and coordinated multiple simultaneous campaigns across government, defense, financial services, media, energy, pharmaceutical, manufacturing, aerospace, non‑profit, aviation, chemical, nuclear and critical‑infrastructure sectors. The attacker’s toolset combines legacy tools such as XAgent, X‑Tunnel, WinIDS, Foozer and DownRange with newer payloads like CredoMap (a credential stealer) and Havex RAT. GreedyBear also injects malicious PowerShell code disguised as Windows updates to maintain persistence and evade detection. Their supply‑chain compromise strategy leverages CVE‑2022‑30190 (Follina) and the recently disclosed Outlook zero‑day (CVE‑2023‑23397) to gain initial access via spearphishing attachments. Operatively, GreedyBear runs a centralized command‑and‑control network where malicious domains resolve to a single IP address, enabling real‑time exfiltration over standard C2 protocols. They use dynamic code injection and continuous malware updates powered by AI‑generated scripts, ensuring rapid adaptability and resistance to signature‑based defenses.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Media
Energy
Pharmaceutical
Manufacturing
Aerospace
Non profit
Aviation
Critical infrastructure
Chemical
Nuclear

Targeted Countries / Regions

RU
UA
US
CN
NL
FR
GB
BY

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

GreedyBear, also known as APT28/Fancy Bear, is a sophisticated threat actor combining financial theft with espionage objectives. Their latest campaign centered on hijacked Firefox extensions and malicious executables that captured cryptocurrency wallet credentials and stolen more than $1 million in crypto. The operation uses supply‑chain compromise, obfuscation, and centralized C2 infrastructure, expanding to multiple browsers and leveraging AI‑generated code for stealth.

Goals & Targeting

GreedyBear’s strategic objectives blend monetary gain with broader intelligence collection. While the primary motivation appears financial—evidenced by large sums of cryptocurrency stolen—they also target state actors, defense contractors, media outlets, and critical infrastructure across Ukraine, NATO members and European states. The dual focus allows them to collect sensitive data for geopolitical leverage while monetizing compromised accounts through wallet credential theft.

Enhanced Description

Key Capabilities

  • Phishing via spoofed domains
  • Credential harvesting through fake login pages
  • Distributing malicious browser extensions (Firefox wallet)
  • Concurrent multi‑campaign operations
  • Cross‑platform implants and droppers (XAgent, X‑Tunnel, WinIDS, Foozer, DownRange)
  • Supply chain infiltration
  • Dynamic obfuscation of files and code
  • Phishing‑based social engineering to install extensions
  • Persistent command‑and‑control communication for real‑time exfiltration
  • Dynamic code injection
  • Continuous malware updates and adaptation
  • Spearphishing with malicious attachments
  • Exploiting software vulnerabilities (Follina, Outlook zero‑day)
  • Deploying credential theft malware CredoMap via RCE
  • Using legitimate tools like PowerShell to execute commands disguised as system updates

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Defense Evasion
Command & Control
Exfiltration

ATT&CK Techniques

T1566.001
T1555.003
T1105
T1195
T1027
T1041
T1566
T1204
T1086
T1190

Software / Tooling

XAgent
X‑Tunnel
WinIDS
Foozer
DownRange
Havex RAT
Emotet
CredoMap

Campaigns & Victims

Since 2008, GreedyBear has executed large‑scale, multi‑phase campaigns against government and critical infrastructure worldwide. The operator typically launches simultaneous attacks across multiple vectors—phishing, malicious browser extensions, credential stealers, and supply‑chain exploits—maintaining a centralized C2 network that simplifies exfiltration and rapid update of payloads. Their past operations include phishing lures exploiting the Follina vulnerability to deliver CredoMap, an Outlook zero‑day in December 2023 against European government networks, and earlier intrusions into the German Bundestag (2015) and France’s TV5 Monde (2015). The actor consistently targets defense, aerospace, media, energy, pharmaceutical and financial sectors, prioritizing high‑value accounts to facilitate both intelligence gathering and illicit cryptocurrency transactions.

IOC Patterns

  • Domain names that imitate legitimate organizations
  • Malicious browser extensions with deceptive behavior
  • Supply‑chain compromise indicators
  • Obfuscated files or code
  • Persistent C2 connections
  • Phishing emails
  • Spearphishing attachments
  • Exploits of CVE‑2022‑30190 (Follina)
  • Exploits of CVE‑2023‑23397 (Outlook zero‑day)
  • Malicious PowerShell commands disguised as Windows updates

Recommended Actions

  • Implement phishing awareness training and simulated exercises for users
  • Block and monitor malicious Firefox wallet extensions via browser security policies
  • Filter or block newly registered domains that mimic legitimate corporate names
  • Enforce multi‑factor authentication across all critical accounts to mitigate credential harvesting
  • Apply robust email filtering rules and user education to deter spearphishing attempts
  • Deploy application whitelisting for web browsers to prevent unapproved extensions
  • Monitor outbound traffic for anomalous C2 communications over standard ports (e.g., 53, 80/443)
  • Leverage behavioral analytics and EDR solutions to detect obfuscated file execution patterns
  • Validate software supply chains with signed code verification and continuous monitoring
  • Maintain up‑to‑date threat intelligence feeds covering known malicious domains, IPs, and hash signatures
  • Enable automatic patching or apply hotfixes for Office/Outlook vulnerabilities (CVE‑2022‑30190, CVE‑2023‑23397)
  • Restrict unapproved PowerShell execution via application control or group policy
  • Detect and respond to unauthorized credential theft activity such as CredoMap signatures

Suggested Tags

APT28
Fancy Bear
GreedyBear
Spearphishing
Malicious-Extension
Credential-Harvest
Phish-Site
Supply-Chain Compromise
Obfuscation
Command‑and‑Control
Persistence
Dynamic Code Injection
Exfiltration
Vulnerability Exploitation
Follina
Outlook Zero-Day
Russian GRU

Confidence Assessment

The analysis is based on publicly available reports and known indicators shared by security vendors, yielding high confidence in the actor’s capabilities and techniques related to malicious extensions, phishing, and credential theft. However, attribution remains partially ambiguous due to overlapping aliases (APT28/Fancy Bear). Information gaps exist regarding precise timelines for recent operations, the full extent of autonomous vs. state‑directed activities, and detailed infrastructure mapping beyond central C2 addresses. Continuous monitoring is required to confirm any changes in tactics or new exploit vectors.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 Filename 1 Email Address 1

References

  1. www.huntandhackett.com — Cited by web research for: Pawn Storm
  2. www.rescana.com — Cited by web research for: T1195
  3. www.koi.ai — Cited by web research for: Exodus
  4. www.crowdstrike.com — Cited by web research for: Astaroth
  5. https://www.darkreading.com/apt28-nuke-themed-follina-exploit-campaign — Cited by AI analysis.

Intel Summary

11

Techniques

64

Tools

7

Campaigns

37

IOCs

0

Observed Data

7

Tactics

Tags

Financial Targeting
Financial Fraud
Malware
Spear-phishing
Cryptocurrency
APT28
Fancy Bear
GreedyBear
Spearphishing
Malicious-Extension
Credential-Harvest
Phish-Site
Supply-Chain Compromise
Obfuscation
Command‑and‑Control
Persistence
Dynamic Code Injection
Exfiltration
Vulnerability Exploitation
Follina
Outlook Zero-Day
Russian GRU

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.