NEW: Group Profiler — instant APT intel lookup. Try it →

APT28

G0007 Russia Espionage MITRE ATT&CK →

Also known as: IRON TWILIGHT · SNAKEMACKEREL · Swallowtail · Group 74 · Sednit · Sofacy · Pawn Storm · Fancy Bear · STRONTIUM · Tsar Team · Threat Group-4127 · TG-4127 · Forest Blizzard · FROZENLAKE · GruesomeLarch

Overview

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Naming & attribution

APT28 is tracked under 16 names across the industry. It uses 93 documented ATT&CK techniques — more than 98% of the 174 groups tracked here. Activity attributed since at least 2004.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
IRON TWILIGHTSecureworks CTU
SNAKEMACKERELAccenture Security
SwallowtailSymantec Security Response
Group 74Mercer, W., et al
SednitFireEye iSIGHT Intelligence
SofacyFireEye
Pawn StormSecureWorks Counter Threat Unit Threat Intelligence
Fancy BearAlperovitch, D.
STRONTIUMKaspersky Lab's Global Research and Analysis Team
Tsar TeamESET
Threat Group-4127SecureWorks Counter Threat Unit Threat Intelligence
TG-4127SecureWorks Counter Threat Unit Threat Intelligence
Forest BlizzardMicrosoft
FROZENLAKEBilly Leonard
GruesomeLarchKoessel, Sean. Adair, Steven. Lancaster, Tom
APT28FireEye

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1001.001 Junk Data — used by 1 of 174 groups
  • T1092 Communication Through Removable Media — used by 1 of 174 groups
  • T1137.002 Office Test — used by 1 of 174 groups
  • T1213 Data from Information Repositories — used by 1 of 174 groups
  • T1498 Network Denial of Service — used by 1 of 174 groups
  • T1546.015 Component Object Model Hijacking — used by 1 of 174 groups
  • T1557.004 Evil Twin — used by 1 of 174 groups
  • T1669 Wi-Fi Networks — used by 1 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT32 Vietnam — 33 shared techniques (24% overlap)
  • Magic Hound Iran — 33 shared techniques (24% overlap)
  • Dragonfly Russia — 29 shared techniques (24% overlap)
  • menuPass China — 27 shared techniques (24% overlap)
  • Threat Group-3390 China — 28 shared techniques (23% overlap)
  • APT39 Iran — 27 shared techniques (23% overlap)

Malware families with current indicators

3 families attributed to APT28, carrying 165 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Koadic 157 indicators
  • Coreshell 5 indicators
  • Zebrocy 3 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Government · Military · Security Service

Regions

Afghanistan · Armenia · Asia Pacific Economic Cooperation · Belgium · China · European Commission · France · Georgia · Germany · Hungary · International Association of Athletics Federations · Japan · Jordan · Kazakhstan · Mongolia · NATO · OSCE · Pakistan · Poland · Tajikistan · Turkey · Ukraine · United Kingdom · United States · World Anti-Doping Agency

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190, T1203, T1211
  • Custom malware/implant development — ATT&CK: 19 attributed custom malware families

TTPs — 93 techniques across 15 tactics

Resource Development

Defense Impairment

Credential Access

Tools & malware (29)

Wevtutil · certutil · CHOPSTICK · Net · Forfiles · DealersChoice · Mimikatz · ADVSTORESHELL · Cannon · Komplex · HIDEDRV · JHUHUGIT · Koadic · Winexe · Responder · cipher.exe · XTunnel · Drovorub · LAMEHUG · Tor · CORESHELL · OLDBAIT · Downdelph · XAgentOSX · USBStealer · Zebrocy · reGeorg · Fysbis · LoJax

Reporting (3)