Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, SIG40, Grizzly Steppe, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, T-APT-12, APT-C-20, UAC-0028, UAC-0001, BlueDelta, APT28, military entities, tracked as, various other epithets, is the most recognizable, has engaged, Sofacy Group, AKA Fancy Bear, a notorious APT group, the tactics, targets, tools, Sandworm Team, Xagent, aka CHOPSTICK, NETUI, EVILTOSS, a few others, DNS poisoning, the Sednit Gang, LAKE RELIC, CHOPSTICK, ADVSTORESHELL, Zebrocy, DNS redirection

Description

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Healthcare
Transportation
Aviation
Hospitality
Chemical
Think tank
Information technology
Media
Financial services
Maritime
Critical infrastructure
Non profit
Telecommunications
Nuclear
Oil gas
Education
Construction
Utilities

Targeted Countries / Regions

US
RU
UA
GB
CN
FR
TR
NL
RO
DE
KZ

AI Analysis

· 1 week ago

Executive Summary

APT28, also known as IRON TWILIGHT or Fancy Bear, is a highly sophisticated Russian state-sponsored cyber threat group linked to the GRU's Unit 26165. They primarily target government and defense sectors with espionage activities, including high-profile compromises of U.S. political campaigns. Their operations demonstrate advanced technical capabilities and a focus on long-term intelligence collection.

Goals & Targeting

APT28's strategic objectives are centered around espionage, particularly targeting the U.S. government, defense sector, and critical infrastructure. Their attacks are designed to gather sensitive political, military, and scientific information. The group's focus on sectors like government, defense, and chemical laboratories suggests a desire to undermine global stability and gain strategic advantages for Russia. Their victims include not only political targets but also organizations involved in international sports and anti-doping agencies, indicating a broader interest in weakening adversaries through cyber means.

Enhanced Description

APT28 is a well-known Russian state-sponsored cyber threat group, widely believed to be linked to the General Staff Main Intelligence Directorate (GRU) Unit 26165. The group has been active since at least 2004 and is known for its involvement in high-profile attacks, including the compromise of the Hillary Clinton campaign and Democratic National Committee (DNC) during the 2016 U.S. presidential election. APT28's activities have been consistently attributed to Russian state-sponsored cyber espionage efforts, with strong evidence linking the group to Russia's military intelligence apparatus. The group has demonstrated a long-standing operational presence and advanced technical capabilities, including the use of custom malware, spearphishing campaigns, and persistence techniques. Their primary focus appears to be on gathering sensitive intelligence from government and defense-related targets, though they have also targeted other sectors such as chemical laboratories and sports organizations. APT28's operations are often conducted in conjunction with other Russian threat groups, including Sandworm Team (Unit 74455), and they have a history of using sophisticated tools to achieve their objectives.

Key Capabilities

  • Custom malware development
  • Spearphishing campaigns
  • Use of web shells
  • Persistence techniques
  • Credential dumping
  • Network intrusions
  • Lateral movement

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Exfiltration
Defense Evasion
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1059.003
T1113
T1056.001
T1498
T1211
T1078
T1560
T1595.002
T1098

Software / Tooling

Downdelph
reGeorg
Zebrocy
Dealer's Choice
Dropuctor
HIDEDRV
Komplex
ADVSTORESHELL

Campaigns & Victims

APT28 is known for its long-term, patient campaigns that often involve multiple phases of lateral movement and persistence. Notable operations include the DNC hack in 2016, compromises of U.S. nuclear facilities, and attacks on anti-doping agencies. The group's operational tempo typically involves short bursts of highly targeted activity followed by periods of low visibility. APT28 frequently uses legitimate tools and techniques in a time-bounding manner to avoid detection, making their campaigns challenging to identify without advanced threat intelligence.

IOC Patterns

  • Spearphishing emails with malicious attachments or links
  • Use of custom malware for persistence
  • Network traffic associated with known GRU-linked TTPs
  • Lateral movement via RDP or PSREMOTE
  • Unusual credential dumping activities
  • Presence of web shells in targeted environments

Recommended Actions

  • Implement continuous monitoring for known APT28 TTPs, including lateral movement and persistence techniques.
  • Conduct regular security assessments and implement network segmentation to limit attack surface.
  • Use threat intelligence feeds to detect and block domains, IPs, and tools associated with APT28.
  • Train employees on identifying advanced phishing attempts and suspicious email patterns.
  • Patch systems and remove administrative shares to mitigate known vulnerabilities exploited by APT28.

Suggested Tags

APT
State-sponsored
Espionage
Government
Defense

Confidence Assessment

Confidence in APT28's attribution to Russian GRU Unit 26165 is high due to multiple indictments and public disclosures from U.S. authorities. However, gaps remain regarding the group's exact operational timeline and specific campaigns prior to 2016. The sophistication of their tools and techniques suggests a highly skilled team, but some details about their full capabilities and campaign scope remain unclear.

ATT&CK Techniques

Collection
15 techniques
Command & Control
13 techniques
Credential Access
10 techniques
Execution
7 techniques
Initial Access
5 techniques
Lateral Movement
6 techniques
Persistence
9 techniques
Reconnaissance
7 techniques
Resource Development
11 techniques
Stealth
19 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. Accenture SNAKEMACKEREL Nov 2018 — Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.
  2. Crowdstrike DNC June 2016 — Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
  3. Leonard TAG 2023 — Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.
  4. US District Court Indictment GRU Oct 2018 — Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.
  5. GRIZZLY STEPPE JAR — Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017.
  6. ESET Zebrocy May 2019 — ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.
  7. ESET Sednit Part 3 — ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.
  8. Sofacy DealersChoice — Falcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.
  9. FireEye APT28 January 2017 — FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.
  10. FireEye APT28 — FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  11. Ars Technica GRU indictment Jul 2018 — Gallagher, S. (2018, July 27). How they did it (and will likely try again): GRU hackers vs. US elections. Retrieved September 13, 2018.
  12. TrendMicro Pawn Storm Dec 2020 — Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.
  13. Securelist Sofacy Feb 2018 — Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.
  14. Kaspersky Sofacy — Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.
  15. Nearest Neighbor Volexity — Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.
  16. Palo Alto Sofacy 06-2018 — Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.
  17. Talos Seduploader Oct 2017 — Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.
  18. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  19. Microsoft STRONTIUM New Patterns Cred Harvesting Sept 2020 — Microsoft Threat Intelligence Center (MSTIC). (2020, September 10). STRONTIUM: Detecting new patterns in credential harvesting. Retrieved September 11, 2020.
  20. Microsoft STRONTIUM Aug 2019 — MSRC Team. (2019, August 5). Corporate IoT – a path to intrusion. Retrieved August 16, 2019.
  21. DOJ GRU Indictment Jul 2018 — Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
  22. Cybersecurity Advisory GRU Brute Force Campaign July 2021 — NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
  23. NSA/FBI Drovorub August 2020 — NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.
  24. SecureWorks TG-4127 — SecureWorks Counter Threat Unit Threat Intelligence. (2016, June 16). Threat Group-4127 Targets Hillary Clinton Presidential Campaign. Retrieved August 3, 2016.
  25. Secureworks IRON TWILIGHT Active Measures March 2017 — Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.
  26. Secureworks IRON TWILIGHT Profile — Secureworks CTU. (n.d.). IRON TWILIGHT. Retrieved February 28, 2022.
  27. Symantec APT28 Oct 2018 — Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.
  28. attack.mitre.org — Cited by web research for: Sandworm Team
  29. apt.etda.or.th — Cited by web research for: Xagent
  30. www.ncsc.gov.uk — Cited by web research for: DNS poisoning
  31. www.huntress.com — Cited by web research for: Spear-phishing
  32. cloud.google.com — Cited by web research for: China

Intel Summary

117

Techniques

59

Tools

6

Campaigns

45

IOCs

0

Observed Data

15

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
State-sponsored
Espionage
Government
Defense

Details

MITRE ID
G0007
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
May 26, 2026
STIX ID
intrusion-set--bef4c620-0787-42a8-a96d-b7eb6e85917c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.