TA422 is a Russian state-sponsored cyberespionage actor attributed to the Russian General Staff Main Intelligence Directorate (GRU), specifically Unit 26165. Its activity overlaps with clusters known as APT28, Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm, and BlueDelta. It targets government, diplomatic, military and defense, aerospace, transportation, technology, finance, manufacturing, education, construction, and consulting organizations, with documented campaigns across Europe and North America and repeated targeting of Ukraine. The actor conducts sustained phishing campaigns using geopolitical themes, impersonated institutions, malicious attachments, and exploit-bearing documents. Its exploitation of CVE-2023-23397 in Microsoft Outlook captures NTLM authentication material without user interaction, while campaigns exploiting CVE-2023-38831 in WinRAR trigger code execution and follow-on credential collection. Some campaigns have involved unusually high message volumes and repeated exploitation attempts against individual accounts. TA422 also uses browser fingerprinting and geolocation checks to filter recipients before delivering payloads, DLL sideloading for execution, and compromised routers as command-and-control nodes or NTLM listeners. In October 2024, TA422 used Google Sheets- and reCAPTCHA-themed ClickFix lures against Ukrainian entities, persuading victims to execute PowerShell commands that established an SSH tunnel and ran Metasploit. In January 2026, it weaponized Microsoft Office vulnerability CVE-2026-21509 within 24 hours of public disclosure against Ukrainian government agencies and European defense, transportation, and diplomatic entities. These exploitation chains deployed the NotDoor Outlook backdoor and Covenant Grunt implants and used cloud storage services for command-and-control communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
TA422 used the vulnerabilities as initial access... The vulnerabilities included CVE-2023-23397—a Microsoft Outlook elevation of privilege flaw that allows a threat actor to exploit TNEF files and initiate NTLM negotiation, obtaining a hash of a target’s NTLM password.
Proofpoint researchers also identified TA422 campaigns leveraging a WinRAR remote execution vulnerability, CVE-2023-38831... The messages contained RAR file attachments that leveraged CVE-2023-38831 to drop a .cmd file...
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
The flaw was exploited as a zero-day alongside CVE-2026-21513 by TA422 in attacks targeting Ukraine and EU member states beginning in late 2025.
1 more CVE tied to this actor tracked in Mallory.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Acteurs de menace # TA488 (state-sponsored) ... TA422 (state-sponsored) ...
Referenced for attribution comparison as a separate GRU-linked espionage cluster distinct from TA458.
Referenced as a Russian GRU-associated contemporary and historical comparator for TA488. The report describes TA422's exploitation of webmail XSS vulnerabilities and its collection of mailbox credentials and email data.
Referenced as an example of a threat actor opportunistically exploiting public proof-of-concept code for network-facing vulnerabilities in 2026; not specifically tied to exploitation of CVE-2026-42055 in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.