APT28 — APT Profile
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, SIG40, G0007, ATK5, Fighting Ursa, ITG05, Blue Athena, TA422, T-APT-12, APT-C-20, UAC-0028, UAC-0001, BlueDelta, LAKE RELIC
IntelFusions coverage (11)
- Russia's APT28 hides its spy traffic in a free web tool 2026-08-27 · Nation-State
- State hackers now log in instead of dropping malware 2026-08-20 · Nation-State
- Most AI attacks are still fake installers, Sophos finds 2026-08-19 · AI Security
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14 · Nation-State
- Google warns Russia's influence network is pivoting from Ukraine back to the West 2026-06-29 · Nation-State
- US Agencies Warn Russian Spies Still Phishing Messaging Apps 2026-06-27 · Nation-State
- Russia's APT28 hackers move to disposable malware and AI-driven tools 2026-06-11 · Nation-State
- Gamaredon Group: Russia's Most Prolific APT Against Ukraine, Powered by Custom Malware and SFX Persistence 2026-02-16 · Nation-State
- The Enigmatic Energetic Bear: Russia's Most Successful Critical Infrastructure Intruder You've Never Heard Of 2026-02-16 · Nation-State
- APT28 Weaponizes CVE-2026-21509 Zero-Day in Operation Neusploit Targeting Eastern Europe 2026-02-02 · Nation-State
- CERT-UA Issues Danger Bulletin as APT28 Exploits CVE-2026-21509 Against Ukraine and EU Governments 2026-02-01 · Nation-State
Tools & malware
- ADVSTORESHELL Backdoor
- apk.popr-d30 Mobile Malware
- Cannon Backdoor
- certutil LOLBin
- CHOPSTICK Backdoor
- cipher.exe LOLBin
- CORESHELL Backdoor
- DealersChoice Exploit
- Downdelph Downloader
- Drovorub Rootkit
- elf.xagent Backdoor
- Forfiles LOLBin
- Fysbis Backdoor
- HIDEDRV Rootkit
- ios.xagent Mobile Malware
- JHUHUGIT Dropper
- js.spypress Infostealer
- Koadic Post-Exploitation Framework
- Komplex Backdoor
- LoJax UEFI Rootkit
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- OLDBAIT Backdoor
- osx.komplex Backdoor
- osx.xagent Backdoor
- ps1.steelhook Backdoor
- py.lamehug Backdoor
- py.masepie Backdoor
- reGeorg Tunneling Tool
- Responder Network Toolkit
- Tor Anonymization Tool
- USBStealer Exfiltration Tool
- Wevtutil Discovery
- win.arguepatch Backdoor
- win.beardshell Backdoor
- win.caddywiper Wiper
- win.cannon Backdoor
- win.computrace Backdoor
- win.coreshell Backdoor
- win.credomap Backdoor
- win.downdelph Backdoor
- win.driveocean Backdoor
- win.fusiondrive Backdoor
- win.gonepostal POS Malware
- win.gooseegg Exploit
- win.graphite Backdoor
- win.koadic Post-Exploitation Framework
- win.lojax UEFI Rootkit
- win.mocky_lnk Backdoor
- win.oceanmap Backdoor
- win.oldbait Backdoor
- win.pocodown Backdoor
- win.sedreco Backdoor
- win.seduploader Downloader
- win.slimagent Backdoor
- win.unidentified_078 Backdoor
- win.unidentified_114 Backdoor
- win.xagent Backdoor
- win.xp_privesc Backdoor
- win.xtunnel Tunneling Tool
Vendor research
- IRON TWILIGHT Secureworks CTU
- APT28: At the Center of the Storm FireEye iSIGHT Intelligence
- The original report Recorded Future
- Zscaler ThreatLabz Zscaler ThreatLabz
- Threat Group-4127 Targets Hillary Clinton Presidential Campaign SecureWorks Counter Threat Unit Threat Intelligence
- How Microsoft names threat actors Microsoft
- APT28: New Espionage Operations Target Military and Government Organizations Symantec Security Response
- IRON TWILIGHT Supports Active Measures Secureworks CTU
- Sofacy Uses DealersChoice to Target European Government Agency Sofacy
- APT28: At the Center of the Storm FireEye
- APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS? FireEye
- How they did it (and will likely try again): GRU hackers vs. US elections Ars Technica
- Pawn Storm’s Lack of Sophistication as a Strategy TrendMicro
- A Slice of 2017 Sofacy Activity Securelist
- Sofacy APT hits high profile targets with updated toolset Kaspersky
- The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access Nearest Neighbor
- Sofacy Group’s Parallel Attacks Palo Alto
- Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al DOJ
- STRONTIUM: Detecting new patterns in credential harvesting Microsoft
- Corporate IoT – a path to intrusion Microsoft
- Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments Cybersecurity Advisory GRU Brute Force Campaign
- Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware NSA
- Threat Group-4127 Targets Hillary Clinton Presidential Campaign Secureworks
- IRON TWILIGHT Supports Active Measures Secureworks
- Secureworks CTU. (n.d.). IRON TWILIGHT Secureworks
Countries linked to this actor
- Estonia targets
- Sweden targets
- Finland targets
- Lithuania targets
- United States targets
- Germany targets
- France targets
- Ukraine targets
- Poland targets
- Italy targets
- Turkey targets
- Netherlands targets
- Brazil targets
- Czech Republic targets
- Moldova targets
- Switzerland targets
- Russia origin
- Denmark targets
- United Kingdom targets
- Armenia targets
- Georgia targets
- Jordan targets
- Slovakia targets
- Greece targets
- Norway targets
- Romania targets
- Portugal targets
- Belgium targets
- Mexico targets
- Azerbaijan targets