APT28 is a Russian state-sponsored cyberespionage actor attributed to the Russian military intelligence service’s GRU 85th Main Special Service Center, military unit 26165. Active since at least 2004, it is also known as Fancy Bear, Forest Blizzard, STRONTIUM, Fighting Ursa, Sednit, Sofacy, Pawn Storm, SNAKEMACKEREL, Swallowtail, Group 74, Tsar Team, and Threat Group-4127. Its targets include government institutions, military organizations, political campaigns, international organizations, anti-doping bodies, and other strategically significant civilian entities. Its operations combine remote intrusions with close-access deployments, including attacks against wireless networks. APT28 conducts large-scale vulnerability scanning, spearphishing with malicious documents and archives, credential harvesting, password spraying, and distributed brute-force attacks. It exploits public-facing applications and network devices, including vulnerable Microsoft Exchange servers and Cisco routers, and uses stolen or default credentials for initial and continued access. It has used a Kubernetes cluster to distribute password attacks and Tor and commercial VPN services to conceal their origin. Post-compromise techniques include credential dumping with Mimikatz and custom tools, keylogging, OAuth access-token abuse, privilege-escalation exploits, pass-the-hash, and exploitation of remote SMB services for lateral movement. The actor collects email, documents, screenshots, and information from local systems, network shares, and collaboration platforms. It stages and compresses stolen information before exfiltration through encrypted web traffic or cloud services. Persistence mechanisms include web shells, startup execution, COM hijacking, bootkits, and the LoJax UEFI rootkit. USB-based tooling supports collection and transfer of information from air-gapped systems. Its associated malware includes CHOPSTICK, ADVSTORESHELL, CORESHELL, Downdelph, JHUHUGIT, XTunnel, and USBStealer. Defense-evasion methods include payload obfuscation, utility renaming, hidden execution, log clearing, file deletion, and timestomping. Notable operations include compromises of U.S. Democratic political organizations and the Hillary Clinton campaign during the 2016 presidential election, attacks against anti-doping organizations, and an attempted close-access operation against the Organisation for the Prohibition of Chemical Weapons in the Netherlands. Other documented targets include Ukrainian users, Malaysian institutions involved in the MH17 investigation, and sports officials attending a conference in Switzerland. APT28 also conducted a denial-of-service attack against the World Anti-Doping Agency. GRU Unit 74455, associated with the separate Sandworm actor, assisted some operations involving APT28.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
79 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
52 malware families attributed to this actor across reporting.
47 additional families tracked in Mallory.
36 CVEs this actor has used in observed campaigns. 36 of them exploited in the wild.
Recently Exploited Vulnerabilities by Fancy Bear: CVE-2023-23397, CVE-2023-38831, CVE-2023-20085.
In January, Russia’s APT28 launched “Operation Neusploit,” exploiting a Microsoft Office zero-day (CVE-2026-21509) within days of discovery to target Ukrainian defense institutions and allied governments.
On June 20, 2022, Malwarebytes Threat Intelligence identified a document weaponized with the Follina (CVE-2022-30190) exploit to download and execute a .NET credential stealer. The article reports this as its first observation of APT28 using Follina.
A critical vulnerability in Synacor Zimbra Collaboration Suite, tracked as CVE-2025-66376, has been exploited by Russian state-sponsored threat actors in targeted attacks against Western governments and Ukraine. The flaw is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI, where a malicious HTML email abuses CSS @import directives to execute arbitrary JavaScript when opened in a vulnerable webmail session.
APT28 has exploited CVE-2014-4076, CVE-2015-2387, CVE-2015-1701, CVE-2017-0263 to escalate privileges.
31 more CVEs tied to this actor tracked in Mallory.
1,756 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in an infrastructure-investigation example illustrating VirusTotal's new scanning capabilities. Researchers used fingerprints and service characteristics to discover additional hosts, but the article explicitly cautions that historical associations do not establish current APT28 ownership or attribution. No specific operation is attributed to APT28.
Previously exploited multiple Roundcube vulnerabilities to compromise Ukrainian government email systems.
Mentioned as the evocative name applied to Russian military intelligence activity, illustrating how branding can distort perceptions of threat actors.
Conducted cyber-espionage against Ukrainian government email systems by exploiting multiple Roundcube vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.