APT28 — APT Profile
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Also tracked as
IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
Tools & malware
- ADVSTORESHELL Backdoor
- apk.popr-d30 Mobile Malware
- Cannon Backdoor
- certutil LOLBin
- CHOPSTICK Backdoor
- cipher.exe LOLBin
- CORESHELL Backdoor
- DealersChoice Exploit
- Downdelph Downloader
- Drovorub Rootkit
- elf.xagent Backdoor
- Forfiles LOLBin
- Fysbis Backdoor
- HIDEDRV Rootkit
- ios.xagent Mobile Malware
- JHUHUGIT Dropper
- js.spypress Infostealer
- Koadic Post-Exploitation Framework
- Komplex Backdoor
- LoJax UEFI Rootkit
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- OLDBAIT Backdoor
- osx.komplex Backdoor
- osx.xagent Backdoor
- ps1.steelhook Backdoor
- py.lamehug Backdoor
- py.masepie Backdoor
- reGeorg Tunneling Tool
- Responder Network Toolkit
- Tor Anonymization Tool
- USBStealer Exfiltration Tool
- Wevtutil Discovery
- win.arguepatch Backdoor
- win.beardshell Backdoor
- win.caddywiper Wiper
- win.cannon Backdoor
- win.computrace Backdoor
- win.coreshell Backdoor
- win.credomap Backdoor
- win.downdelph Backdoor
- win.driveocean Backdoor
- win.fusiondrive Backdoor
- win.gonepostal POS Malware
- win.gooseegg Exploit
- win.graphite Backdoor
- win.koadic Post-Exploitation Framework
- win.lojax UEFI Rootkit
- win.mocky_lnk Backdoor
- win.oceanmap Backdoor
- win.oldbait Backdoor
- win.pocodown Backdoor
- win.sedreco Backdoor
- win.seduploader Downloader
- win.slimagent Backdoor
- win.unidentified_078 Backdoor
- win.unidentified_114 Backdoor
- win.xagent Backdoor
- win.xp_privesc Backdoor
- win.xtunnel Tunneling Tool
Vendor research
- Zscaler ThreatLabz Zscaler ThreatLabz
- Threat Group-4127 Targets Hillary Clinton Presidential Campaign SecureWorks Counter Threat Unit Threat Intelligence
- IRON TWILIGHT Supports Active Measures Secureworks CTU
- How Microsoft names threat actors Microsoft
- APT28: New Espionage Operations Target Military and Government Organizations Symantec Security Response
- APT28: At the Center of the Storm FireEye iSIGHT Intelligence
- IRON TWILIGHT Secureworks CTU
- En Route with Sednit - Part 3: A Mysterious Downloader ESET
- Sofacy Uses DealersChoice to Target European Government Agency Sofacy
- APT28: At the Center of the Storm FireEye
- APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS? FireEye
- How they did it (and will likely try again): GRU hackers vs. US elections Ars Technica
- Pawn Storm’s Lack of Sophistication as a Strategy TrendMicro
- A Slice of 2017 Sofacy Activity Securelist
- Sofacy APT hits high profile targets with updated toolset Kaspersky
- The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access Nearest Neighbor
- Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al DOJ
- "Cyber Conflict" Decoy Document Used in Real Cyber Conflict Talos
- STRONTIUM: Detecting new patterns in credential harvesting Microsoft
- Corporate IoT – a path to intrusion Microsoft
- Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments Cybersecurity Advisory GRU Brute Force Campaign
- Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware NSA
- Threat Group-4127 Targets Hillary Clinton Presidential Campaign Secureworks
- IRON TWILIGHT Supports Active Measures Secureworks
- Secureworks CTU. (n.d.). IRON TWILIGHT Secureworks