Also known as: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, SIG40, Grizzly Steppe, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, T-APT-12, APT-C-20, UAC-0028, UAC-0001, BlueDelta, APT28, military entities, tracked as, various other epithets, is the most recognizable, has engaged, Sofacy Group, AKA Fancy Bear, a notorious APT group, the tactics, targets, tools, Sandworm Team, Xagent, aka CHOPSTICK, NETUI, EVILTOSS, a few others, DNS poisoning, the Sednit Gang, LAKE RELIC, CHOPSTICK, ADVSTORESHELL, Zebrocy, DNS redirection
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT28, also known as IRON TWILIGHT or Fancy Bear, is a highly sophisticated Russian state-sponsored cyber threat group linked to the GRU's Unit 26165. They primarily target government and defense sectors with espionage activities, including high-profile compromises of U.S. political campaigns. Their operations demonstrate advanced technical capabilities and a focus on long-term intelligence collection.
Goals & Targeting
APT28's strategic objectives are centered around espionage, particularly targeting the U.S. government, defense sector, and critical infrastructure. Their attacks are designed to gather sensitive political, military, and scientific information. The group's focus on sectors like government, defense, and chemical laboratories suggests a desire to undermine global stability and gain strategic advantages for Russia. Their victims include not only political targets but also organizations involved in international sports and anti-doping agencies, indicating a broader interest in weakening adversaries through cyber means.
Enhanced Description
APT28 is a well-known Russian state-sponsored cyber threat group, widely believed to be linked to the General Staff Main Intelligence Directorate (GRU) Unit 26165. The group has been active since at least 2004 and is known for its involvement in high-profile attacks, including the compromise of the Hillary Clinton campaign and Democratic National Committee (DNC) during the 2016 U.S. presidential election. APT28's activities have been consistently attributed to Russian state-sponsored cyber espionage efforts, with strong evidence linking the group to Russia's military intelligence apparatus. The group has demonstrated a long-standing operational presence and advanced technical capabilities, including the use of custom malware, spearphishing campaigns, and persistence techniques. Their primary focus appears to be on gathering sensitive intelligence from government and defense-related targets, though they have also targeted other sectors such as chemical laboratories and sports organizations. APT28's operations are often conducted in conjunction with other Russian threat groups, including Sandworm Team (Unit 74455), and they have a history of using sophisticated tools to achieve their objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT28 is known for its long-term, patient campaigns that often involve multiple phases of lateral movement and persistence. Notable operations include the DNC hack in 2016, compromises of U.S. nuclear facilities, and attacks on anti-doping agencies. The group's operational tempo typically involves short bursts of highly targeted activity followed by periods of low visibility. APT28 frequently uses legitimate tools and techniques in a time-bounding manner to avoid detection, making their campaigns challenging to identify without advanced threat intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in APT28's attribution to Russian GRU Unit 26165 is high due to multiple indictments and public disclosures from U.S. authorities. However, gaps remain regarding the group's exact operational timeline and specific campaigns prior to 2016. The sophistication of their tools and techniques suggests a highly skilled team, but some details about their full capabilities and campaign scope remain unclear.
Russian Doll
Bundestag
TV5 Monde Cyber Caliphate
EFF Attack
DNC Hack
OpOlympics
No observed data linked yet.
117
Techniques
59
Tools
6
Campaigns
45
IOCs
0
Observed Data
15
Tactics