Also known as: Fancy Bear, APT28, tracked as, HTTP cookies, browser cookies, simply cookies, a Russian GRU-linked group, conducts sophisticated espionage, information theft campaigns globally, targeting governments, critical infrastructure, WannaCryptor, Fox Kitten, UNC757, India, Russia, Taiwan, Japan, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, Masked Spider, Abyss Locker, Parisite, BlackCat, CamoFei, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, MERCURY, Mango Sandstorm, Static Kitten, TA450, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, DownExPyer, enabling data exfiltration, remote control, 560048
APTLock has emerged as a distinct threat group operating at the intersection of state‑sponsored objectives and cybercrime. The actor uses a dual‑layer approach: first, it delivers custom backdoors via spearphishing attachments or exploitation of publicly disclosed CVEs—including TrueConf vulnerabilities (BDU:2025-10114/10116) and Office exploits—so that initial infection occurs through seemingly legitimate emails from compromised official accounts. Once inside the target network, APTLock’s implant suite—PhantomHeart, PhantomCore, MiniDoor Outlook macro stealer, Covenant grunt, PixyNetLoader, PUMAKIT rootkit—is deployed via PowerShell scripts and Smart Install Maker installers. It establishes persistence through legitimate scheduled tasks masquerading as update scripts, installs a Linux‑level rootkit, or creates a Windows service (T1543.003). The malware exfiltrates gathered credentials (OS credential dumping, browser credential extraction), logs and other state‑sensitive data using SMTP, HTTPS over obfuscated tunnels on cloud storage such as Filen.io or Tor hidden services. Subsequent stages involve ransomware installation: the actor deploys a custom ChaCha20/Curve25519‑based encoder called APTLock.exe (or variants of LockBit) that removes Volume Shadow Copies, disables Security Software Discovery and modifies Image File Execution Options to impede recovery. Ransom notes promise data restoration in exchange for payment while simultaneously leaking exfiltrated files to public leak sites. APTLock’s command‑and‑control infrastructure is intentionally dispersed across public cloud services, obfs4 bridges, and legitimate remote‑control tools like AnyDesk or NetSupport. This multi‑faceted approach not only evades detection but also provides a resilient fallback if one channel is blocked.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APTLock is a hybrid threat actor that blends state‑sponsored espionage with financially driven ransomware operations, leveraging sophisticated phishing, exploitation of public vulnerabilities and cloud‑based command-and-control channels. The group employs modular backdoors (PhantomHeart, MiniDoor, Covenant) to move laterally, steal credentials, and exfiltrate data before deploying chaos encryptors such as APTLock.exe or LockBit. Its operational scope spans critical infrastructure, government, financial services and high‑profile technology vendors across more than 40 countries.
Goals & Targeting
The primary objectives of APTLock revolve around mixed motives: on the one hand, state‑level intelligence gathering across a wide spectrum of critical sectors—government, defense, energy, finance—and on the other, financial gain via ransomware and data monetization. By targeting both high-value organizations and mid‑tier entities in strategic regions such as Eastern Europe, Southeast Asia, and the Middle East, the actor seeks to maximize return either in terms of monetary ransom or actionable espionage data for political leverage.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APTLock has been observed leveraging an extensive mix of phishing attachments, exploitation of publicly disclosed software vulnerabilities (including TrueConf and Office CVEs), and the use of legitimate cloud services for stealthy command‑and‑control. The actor typically commences infiltration via spearphishing email from compromised government accounts, installs a modular backdoor, then expands capabilities to credential harvesting, lateral movement over SMB/RDP/SSH, and data exfiltration via SMTP or encrypted HTTPS channels. The group alternates between espionage (collecting strategic intelligence on critical sectors) and ransomware deployment (encrypting files with ChaCha20/Curve25519 payloads while erasing recovery mechanisms). Operations are rapid—often delivering a full attack chain within days—and span over 40 countries, indicating a high operational tempo and a flexible toolset that can be adapted to the target’s security posture. Notable operations include exploitation of CVE‑2026‑21509 in multiple Eastern European government entities, use of MiniDoor macro stealer, and cloud‑based C2 via Filen.io observed across several campaigns involving APT28 activity signatures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data available demonstrates a reasonable confidence level regarding APTLock’s tactics, techniques, and procedures due to multiple corroborating sources. Attribution to the Russian GRU and designation as APT28 is supported by several analyst mentions, but definitive evidence linking all observed behaviors remains inconclusive. Gaps include precise timelines of operations, full spectrum of used CVEs (some listed only generically), and complete attribution of all tool variants—necessitating ongoing monitoring of new intelligence to refine the actor’s profile.
No campaigns linked yet.
No observed data linked yet.
50
Techniques
67
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics