TA422 is a Russia-linked state-sponsored espionage threat actor widely associated with APT28 and overlapping with aliases including Sofacy, Fancy Bear, Forest Blizzard, Pawn Storm, and BlueDelta. It has been attributed to Russia’s GRU, specifically Unit 26165 in the supplied reporting. The actor is known for sustained phishing-led intrusion activity, rapid weaponization of newly disclosed vulnerabilities, and targeting aligned with Russian intelligence collection priorities. TA422 has conducted repeated campaigns against organizations in Europe and North America, with especially prominent targeting of Ukrainian government entities and European defense, transportation, and diplomatic organizations. Reported victim sectors include government, defense, aerospace, education, finance, manufacturing, technology, construction, and consulting. Operationally, TA422 is characterized by aggressive initial-access activity through phishing and exploitation of public vulnerabilities, including Microsoft Outlook, WinRAR, and Microsoft Office flaws. It has used malicious documents and archives to trigger credential theft or code execution, including exploitation chains that harvested NTLM material and delivered follow-on implants. The actor has also been observed weaponizing disclosed vulnerabilities within a day of public disclosure, including campaigns using malicious RTF and OLE content against Ukrainian and European targets. The group employs layered delivery and evasion techniques such as spoofed geopolitical or software-update themes, redirection chains, browser fingerprinting, geolocation checks, and use of compromised edge devices or infrastructure for listener and command-and-control functions. Observed execution tradecraft includes LNK-based chains, DLL sideloading, PowerShell-based execution, SSH tunneling, Metasploit, and deployment of implants including NotDoor and Covenant Grunt. TA422 has also adopted the ClickFix social-engineering technique in espionage operations, using fake document-sharing or verification workflows to trick targets into manually executing PowerShell commands. In observed Ukrainian-focused activity, this led to creation of an SSH tunnel and execution of offensive tooling. Overall, TA422 is a mature Russian cyber-espionage actor focused on credential access, initial compromise, and post-compromise access in support of intelligence collection, with a demonstrated ability to blend traditional phishing operations with opportunistic exploitation of newly disclosed vulnerabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
TA422 used the vulnerabilities as initial access... The vulnerabilities included CVE-2023-23397—a Microsoft Outlook elevation of privilege flaw that allows a threat actor to exploit TNEF files and initiate NTLM negotiation, obtaining a hash of a target’s NTLM password.
Proofpoint researchers also identified TA422 campaigns leveraging a WinRAR remote execution vulnerability, CVE-2023-38831... The messages contained RAR file attachments that leveraged CVE-2023-38831 to drop a .cmd file...
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
The flaw was exploited as a zero-day alongside CVE-2026-21513 by TA422 in attacks targeting Ukraine and EU member states beginning in late 2025.
1 more CVE tied to this actor tracked in Mallory.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Acteurs de menace # TA488 (state-sponsored) ... TA422 (state-sponsored) ...
Referenced for attribution comparison as a separate GRU-linked espionage cluster distinct from TA458.
Referenced as an example of a threat actor opportunistically exploiting public proof-of-concept code for network-facing vulnerabilities in 2026; not specifically tied to exploitation of CVE-2026-42055 in this content.
Mentioned as an example of rapid weaponization of newly disclosed CVEs, not as an actor involved in the Sitefinity vulnerability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.