APT28 is a Russian state-sponsored cyber espionage threat actor widely tracked under aliases including Fancy Bear, Sofacy, Sednit, Pawn Storm, Strontium, Forest Blizzard, Fighting Ursa, BlueDelta, Tsar Team, Group 74, TG-4127, UAC-0001, and UAC-0028. The group is associated with long-running intelligence collection and influence-linked operations, including activity against government, military, political, and critical infrastructure targets. It has been publicly linked to Russian operations against U.S. political organizations during the 2016 election period and to broader campaigns targeting NATO-, OSCE-, and regional security-related entities. APT28 is known for spearphishing-led initial access, particularly emails carrying malicious Microsoft Office attachments and macro-enabled documents. The group has also used staged malware delivery chains in which first-stage downloaders retrieve second-stage implants, and it has leveraged PowerShell extensively for payload execution and command execution. Observed tradecraft includes process discovery, screenshot capture, keylogging, hidden or concealed execution, file and artifact hiding, and anti-forensic cleanup such as deleting files to cover tracks. The actor has also used document collection techniques, including searching for office documents and specific terms on compromised systems. The group has demonstrated persistence through mechanisms such as startup-folder malware placement and has used defense-evasion measures including renaming malicious components to resemble legitimate services or pages, changing extensions on exfiltrated files to appear benign, concealing PowerShell windows, and using utilities such as certutil for decoding payloads. Reported tooling and malware associated with APT28 include Zebrocy, including a Go-based variant, as well as Delphi backdoors and loader trojans that enumerate processes and seek suitable execution contexts. APT28 has also been linked to LoJax, a UEFI bootkit, indicating capability extending below the operating system layer. The actor’s operational profile is consistent with a mature state-backed intrusion set focused primarily on espionage, with capabilities spanning initial compromise, stealthy execution, persistence, collection, and exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
36 CVEs this actor has used in observed campaigns. 36 of them exploited in the wild.
2026-02-04 ⋅ StrikeReady ⋅ APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure ... 2026-02-02 ⋅ Zscaler ⋅ APT28 Leverages CVE-2026-21509 in Operation Neusploit
Other campaigns have entailed the exploitation of security flaws in Microsoft Outlook (CVE-2023-23397, CVSS score: 9.8) to plunder NT LAN Manager (NTLM) v2 hashes, raising the possibility that the threat actor may leverage other weaknesses to exfiltrate NTLMv2 hashes for use in relay attacks.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
This ongoing analysis led to the discovery of another zero-day vulnerability utilized in the operation (CVE-2026-21513)... CVE-2026-21513 is another vulnerability within the Microsoft MSHTML framework, specifically located in the _AttemptShellExecuteForHlinkNavigate function of ieframe.dll, the core library of the Internet Explorer browser.
A critical vulnerability in Synacor Zimbra Collaboration Suite, tracked as CVE-2025-66376, has been exploited by Russian state-sponsored threat actors in targeted attacks against Western governments and Ukraine. The flaw is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI, where a malicious HTML email abuses CSS @import directives to execute arbitrary JavaScript when opened in a vulnerable webmail session.
31 more CVEs tied to this actor tracked in Mallory.
1,444 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted 'Operation Neusploit' targeting Ukrainian defense institutions and allied nations, using zero-day vulnerabilities, geofencing, trojans, steganography, and spear-phishing as part of an expanded campaign against defense objectives.
Associated with the AI-enabled PROMPTSTEAL operation deployed in Ukraine.
Mentioned only in related content links, not part of the CaptiveCrunch campaign discussed in this reference.
Targeting critical sectors and remote workers via compromised SOHO routers, including Ubiquiti EdgeRouter devices, to perform DNS hijacking, harvest NTLMv2 hashes and Microsoft 365 tokens, and exploit Outlook credential theft opportunities. The article also references documented exploitation of CVE-2023-23397 by the group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.