Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors aptlock

Also known as: Fancy Bear, APT28, tracked as, HTTP cookies, browser cookies, simply cookies, a Russian GRU-linked group, conducts sophisticated espionage, information theft campaigns globally, targeting governments, critical infrastructure, WannaCryptor, Fox Kitten, UNC757, India, Russia, Taiwan, Japan, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, Masked Spider, Abyss Locker, Parisite, BlackCat, CamoFei, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, MERCURY, Mango Sandstorm, Static Kitten, TA450, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, DownExPyer, enabling data exfiltration, remote control, 560048

Description

APTLock has emerged as a distinct threat group operating at the intersection of state‑sponsored objectives and cybercrime. The actor uses a dual‑layer approach: first, it delivers custom backdoors via spearphishing attachments or exploitation of publicly disclosed CVEs—including TrueConf vulnerabilities (BDU:2025-10114/10116) and Office exploits—so that initial infection occurs through seemingly legitimate emails from compromised official accounts. Once inside the target network, APTLock’s implant suite—PhantomHeart, PhantomCore, MiniDoor Outlook macro stealer, Covenant grunt, PixyNetLoader, PUMAKIT rootkit—is deployed via PowerShell scripts and Smart Install Maker installers. It establishes persistence through legitimate scheduled tasks masquerading as update scripts, installs a Linux‑level rootkit, or creates a Windows service (T1543.003). The malware exfiltrates gathered credentials (OS credential dumping, browser credential extraction), logs and other state‑sensitive data using SMTP, HTTPS over obfuscated tunnels on cloud storage such as Filen.io or Tor hidden services. Subsequent stages involve ransomware installation: the actor deploys a custom ChaCha20/Curve25519‑based encoder called APTLock.exe (or variants of LockBit) that removes Volume Shadow Copies, disables Security Software Discovery and modifies Image File Execution Options to impede recovery. Ransom notes promise data restoration in exchange for payment while simultaneously leaking exfiltrated files to public leak sites. APTLock’s command‑and‑control infrastructure is intentionally dispersed across public cloud services, obfs4 bridges, and legitimate remote‑control tools like AnyDesk or NetSupport. This multi‑faceted approach not only evades detection but also provides a resilient fallback if one channel is blocked.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Financial services
Government
Defense
Energy
Manufacturing
Critical infrastructure
Transportation
Education
Construction
Telecommunications
Maritime
Healthcare
Aerospace
Utilities
Media
Retail
Aviation
Chemical
Nuclear
Mining

Targeted Countries / Regions

US
RU
IN
BR
PL
AE
GB
VN
KP
CN
KZ
RO
UA
IL
TR
PK
IT
DE
NL
JP
TW
BY
NG
SA
MX
ES
IR
FR
EG
AU

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

APTLock is a hybrid threat actor that blends state‑sponsored espionage with financially driven ransomware operations, leveraging sophisticated phishing, exploitation of public vulnerabilities and cloud‑based command-and-control channels. The group employs modular backdoors (PhantomHeart, MiniDoor, Covenant) to move laterally, steal credentials, and exfiltrate data before deploying chaos encryptors such as APTLock.exe or LockBit. Its operational scope spans critical infrastructure, government, financial services and high‑profile technology vendors across more than 40 countries.

Goals & Targeting

The primary objectives of APTLock revolve around mixed motives: on the one hand, state‑level intelligence gathering across a wide spectrum of critical sectors—government, defense, energy, finance—and on the other, financial gain via ransomware and data monetization. By targeting both high-value organizations and mid‑tier entities in strategic regions such as Eastern Europe, Southeast Asia, and the Middle East, the actor seeks to maximize return either in terms of monetary ransom or actionable espionage data for political leverage.

Enhanced Description

Key Capabilities

  • Remote access via HTTP and SSH tunnels
  • Persistence through scheduled tasks masquerading as legitimate update scripts
  • Phishing campaigns with malicious attachments
  • Exploitation of TrueConf vulnerabilities BDU:2025-10114 and BDU:2025-10116 to deliver malware
  • Deployment of PowerShell-based backdoors
  • Custom installer generation using Smart Install Maker
  • Disabling Windows Defender and other security utilities
  • Data exfiltration over SMTP and HTTPS via obfuscated tunnels
  • Remote control via Cobint backdoor
  • Post‑exploitation persistence using a Linux kernel‑level rootkit (PUMAKIT)
  • Infrastructure encryption with Babuk on Linux and LockBit on Windows
  • Embedding shells in .epf files to execute code in 1C software
  • Exploiting publicly disclosed CVEs to gain foothold
  • Phishing emails delivered from compromised government accounts as initial vector
  • Server‑side evasion based on geographic region and User‑Agent headers
  • Use of legitimate cloud storage (Filen.io) for command‑and‑control traffic

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration
Privilege Escalation
Defense Evasion
Credential Discovery
Command and Control
Collection

ATT&CK Techniques

T1047
T1113
T1027.009
T1003
T1129
T1014
T1542.003
T1489
T1543.003
T1119
T1007
T1135
T1082
T1071
T1106
T1202
T1005
T1036
T1055
T1112
T1555.003
T1222
T1548
T1059
T1083
T1552.001
T1057
T1547.001
T1027.005
T1486
T1012
T1518.001
T1564.003
T1485
T1070.004
T1027.002
T1564.001
T1490
T1562.001
T1574.002
T1566.001
T1059.001
T1053.005
T1041
T1190
T1068
T1071.001
T1049
T1105
T1050

Software / Tooling

PhantomHeart
PhantomPxPigeon
PhantomProxyLite
STRRAT (Strigoi Master)
NetSupport
Mirai
AnyDesk
Smart Install Maker
Cobint backdoor
Babuk
LockBit
PUMAKIT rootkit
MiniDoor macro stealer
PixyNetLoader
Covenant Grunt implant
Sliver cross‑platform implant
KrustyLoader malware
Filen.io cloud storage
PhantomCore
APTLock ransomware
GOST tunnel utility
FRPS reverse proxy
Yuze tunneling tool

Campaigns & Victims

APTLock has been observed leveraging an extensive mix of phishing attachments, exploitation of publicly disclosed software vulnerabilities (including TrueConf and Office CVEs), and the use of legitimate cloud services for stealthy command‑and‑control. The actor typically commences infiltration via spearphishing email from compromised government accounts, installs a modular backdoor, then expands capabilities to credential harvesting, lateral movement over SMB/RDP/SSH, and data exfiltration via SMTP or encrypted HTTPS channels. The group alternates between espionage (collecting strategic intelligence on critical sectors) and ransomware deployment (encrypting files with ChaCha20/Curve25519 payloads while erasing recovery mechanisms). Operations are rapid—often delivering a full attack chain within days—and span over 40 countries, indicating a high operational tempo and a flexible toolset that can be adapted to the target’s security posture. Notable operations include exploitation of CVE‑2026‑21509 in multiple Eastern European government entities, use of MiniDoor macro stealer, and cloud‑based C2 via Filen.io observed across several campaigns involving APT28 activity signatures.

IOC Patterns

  • phishing emails containing malicious attachments
  • scheduled task persistence entries masquerading as legitimate update scripts
  • exploitation of TrueConf vulnerabilities BDU:2025-10114/16
  • custom Windows Installer generated with Smart Install Maker
  • encrypted RAR archives with custom password
  • disabling Windows Defender via utilities
  • SSH tunnel deployment for command‑and‑control
  • CVE exploitation list (CVE-2025-4427, CVE-2025-4428, CVE-2025-53770, CVE-2026-21509)
  • use of .epf file extension in 1C attacks
  • MiniDoor binary execution
  • PixyNetLoader binary usage
  • Filen.io domain usage

Recommended Actions

  • Implement organization‑wide email security controls to block malicious attachments and detect spearphishing patterns
  • Patch TrueConf applications against BDU:2025-10114/16 and all referenced CVEs promptly
  • Monitor and restrict automated scheduled tasks; flag those resembling legitimate updates for investigation
  • Detect PowerShell scripts that download from unknown domains or invoke remote code execution
  • Block outbound traffic to known malicious C2 domains/IPs, including Filen.io and identified Tor endpoints
  • Enable alerts on disabling or tampering with Windows Defender and other security services
  • Enforce strict macro policy for Office files; disable automatic macro execution unless digitally signed
  • Deploy endpoint detection to identify rootkits such as PUMAKIT, file packing obfuscation (T1027) and hidden processes (T1564)
  • Filter or monitor use of legitimate remote‑control tools like AnyDesk, NetSupport, and remotely-installed services; verify their legitimacy before deployment
  • Mandate multi‑factor authentication for all privileged and government accounts
  • Conduct regular security awareness training with emphasis on spearphishing recognition
  • Implement network segmentation and least‑privilege controls to limit lateral movement via SMB/RDP/SSH

Suggested Tags

APT28
Fancy Bear
Head Mare
Stan Ghouls
Librarian Likho
Russian GRU‑linked
Phishing attachments
Exploitation public‑facing application
PowerShell scripts
Remote access trojan
Scheduled task persistence
CVE exploitation
Remote backdoor
Rootkit stealth
Cloud-based C2
MiniDoor
PixyNetLoader
Covenant
ExCobalt
QuietCrabs

Confidence Assessment

The data available demonstrates a reasonable confidence level regarding APTLock’s tactics, techniques, and procedures due to multiple corroborating sources. Attribution to the Russian GRU and designation as APT28 is supported by several analyst mentions, but definitive evidence linking all observed behaviors remains inconclusive. Gaps include precise timelines of operations, full spectrum of used CVEs (some listed only generically), and complete attribution of all tool variants—necessitating ongoing monitoring of new intelligence to refine the actor’s profile.

ATT&CK Techniques

Exfiltration
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 Email Address 1 URL 3 Filename 6

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. www.welivesecurity.com — Cited by web research for: WannaCryptor
  3. www.cyfirma.com — Cited by web research for: T1574.002
  4. www.group-ib.com — Cited by web research for: RansomHub
  5. www.trendmicro.com — Cited by web research for: Iran

Intel Summary

50

Techniques

67

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

APT28
Fancy Bear
Head Mare
Stan Ghouls
Librarian Likho
Russian GRU‑linked
Phishing attachments
Exploitation public‑facing application
PowerShell scripts
Remote access trojan
Scheduled task persistence
CVE exploitation
Remote backdoor
Rootkit stealth
Cloud-based C2
MiniDoor
PixyNetLoader
Covenant
ExCobalt
QuietCrabs

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
Iran (IR)
Confidence
80%
Added
Jul 30, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.