Also known as: APT28, tracked as, Pawn Storm, Fancy Bear, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, Sednit
Narketing163—also referenced under aliases such as APT28 and Fancy Bear in various threat reports—has been active since at least July 2023. The actor primarily focuses on financial gain, targeting a wide range of sectors including government, finance, healthcare, defense, critical infrastructure, energy, manufacturing, retail, education, and non‑profit organizations across the United States, Russia, China, Iran, Japan, Ukraine, Kazakhstan, Belgium, Azerbaijan, Turkey, Germany, the UK, India, South Africa, Saudi Arabia, Australia, Singapore, Brazil, Mexico, Spain, Poland, Canada, France, Netherlands, Italy, Lebanon, Azerbaijan, and more. Their campaigns are engineered around sophisticated spearphishing campaigns that use business‑correspondence templates (price quotes, order forms, payment notices) in Russian, Azerbaijani, Turkish, and English to entice victims. Deliverables typically include commodity infostealers such as RedLine Stealer, Agent Tesla, FormBook, and the Snake Keylogger. The malware is packaged in compressed archives and exploits native Windows tools (PowerShell, WMI, PsExec) for execution, lateral movement, and persistence through scheduled tasks, modified services, dormant accounts, and firmware‑level implants where available. Exfiltration flows are routed via actor‑controlled Roundcube mail servers or encrypted channelised C2 infrastructures such as the custom WLDR implant. In addition to classic credential theft, Narketing163 demonstrates a multi‑phase approach that extends into industrial control system environments through OT‑to‑IT bridging and sensor data extraction from water treatment plants and electrical substations. Anti‑forensics behaviors—including clearing event logs, modifying timestamps, executing in memory, and encrypting C2 traffic—are employed to evade detection over prolonged periods. The actor’s publicly documented toolset also includes PlugX for initial credential access, Starland RAT for long‑term persistence, and a suite of open‑source utilities referenced in recent reports (e.g., PowerShell scripts and WMI queries). These assets allow the group to pivot rapidly between financial fraud operations and more sophisticated stealthy espionage or sabotage-oriented objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Narketing163 is a financially motivated threat actor using large‑scale spearphishing campaigns with commodity infostealer and keylogger malware delivered via compressed attachments. Their operations span multiple continents and sectors, employing legitimate credentials, native Windows tools and custom RATs to establish persistence and exfiltrate data through mail servers. Recent activities indicate a shift into OT environments and an increasing use of sophisticated anti‑forensics tactics.
Goals & Targeting
Narketing163’s strategic objective appears to be a two‑fold mix of monetization and data exfiltration. Revenue is generated through traditional keylogging and credential harvesting that enables account takeover for banking or payment fraud, while the acquisition of sensitive organizational data may serve longer‑term espionage or blackmail efforts. Target selection is broad yet heavily weighted toward businesses with high transaction volumes—retail, financial services, logistics—and critical infrastructure organizations where compromised credentials can facilitate lateral movement into OT networks. Geographically, the actor places emphasis on entities within politically volatile regions but also routinely extends operations to Western corporate and governmental targets. The group leverages supply‑chain compromise as a vector whenever feasible, allowing it to infiltrate customers via compromised third‑party software or services—such as popular SaaS tools. By blending legitimate credentials with native Windows administration tools, the actor sustains footholds while obfuscating malicious activity behind benign network traffic. Their tactics are characterized by low‑and‑slow persistence: scheduled tasks or dormant accounts that can be activated on demand, combined with in‑memory execution and encrypted C2 sessions to keep alerts on defense systems muted. These behaviors indicate a long‑term threat model focused on stealth rather than rapid disruption.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Narketing163 first appears in publicly available reports from July 2023 and has intensified activity since then. The actor distributes spearphishing emails bearing legitimate business correspondence, utilizing compressed archives to deliver commodity credential‑stealing payloads. Victim lists are large and globally distributed, covering over 50 countries across every industrial sector of interest. Persistent indicators include scheduled tasks that re‑activate malware on a time‑based cadence, dormant domain accounts, and the use of legitimate mail servers for data exfiltration. Campaign patterns reveal a “low‑and‑slow” posture where the actor establishes footholds, waits for credential harvests to mature, and then transitions into OT networks for sensor data extraction. Notable operations documented in 2024 include infiltration of water‑treatment facilities using custom Starland RATs, with evidence of extracting operational telemetry over encrypted C2 sessions. Operational tempo suggests quarterly or bi‑annual waves corresponding to corporate fiscal cycles, likely tied to financial exploitation windows. While the actor remains officially unidentified in official threat actor catalogs, consistent use of tool signatures and targeting heuristics aligns with publicly documented APT28 activity. Incident response studies have shown that detection fatigue grows when the group employs native Windows tools, making it essential for organizations to refine monitoring around PowerShell scripts, WMI queries, and PsExec usage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence for Narketing163’s operational model is moderate to high, derived from repeated campaign reports detailing spearphishing delivery methods, commodity malware usage, and advanced persistence techniques. Attribution confidence remains tentative since the actor is also linked with publicly known APT28 monikers; however, consistent signatures across tools and tactics strengthen the association. Information gaps persist around precise funding sources, detailed supply‑chain vectors used, firmware‑level implant capabilities, and the full scope of their long‑term strategic objectives beyond financial exploitation.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
50
Tools
0
Campaigns
9
IOCs
0
Observed Data
6
Tactics