APT28
G00077 reportsAnalyst assessment — key judgments
- Signature techniques: T1590.005 (IP Addresses), T1059.001 (PowerShell), T1589.001 (Credentials).
- Primary targeting: RU, US, UA, ES.
- Steady activity: 3 report(s) in last 30d vs 2 prior (+50%).
- Recent movement: 3 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 60% of 25 observed techniques (10 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 4
- CVE-2022-38028KEV1 rpt
- CVE-2026-21510KEV1 rpt
- CVE-2026-21513KEV1 rpt
- CVE-2026-32202KEV1 rpt
Overview
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019)
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
ATT&CK technique matrix
- T1590.005 · IP Addressesconf 653
- T1059.001 · PowerShellconf 653
- T1589.001 · Credentialsconf 653
- T1027.015 · Compressionconf 653
- T1669 · Wi-Fi Networksconf 653
- T1053.005 · Scheduled Taskconf 653
- T1047 · Windows Management Instrumentationconf 602
- T1557 · Adversary-in-the-Middleconf 602
- T1059.007 · JavaScriptconf 602
- T1114 · Email Collectionconf 602
- T1543.003 · Windows Serviceconf 602
- T1559.001 · Component Object Modelconf 602
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|