Mandiant published a report detailing malware and tradecraft associated with APT28, the Russia-linked cyber-espionage group also widely tracked as Fancy Bear. The report describes the intrusion set as part of broader Russian intelligence collection activity, highlighting how the group uses Windows-based malware and operational techniques to gain access, maintain persistence, and support espionage objectives against targeted organizations.
The publication provides defenders with a technical window into APT28 operations by mapping malware usage and intrusion behavior tied to Russian state-aligned campaigns. The report adds to public intelligence on the group’s tooling and methods, giving security teams updated context for threat hunting, detection engineering, and prioritizing monitoring for activity associated with APT28.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
According to Sekoia, APT28 moved away from rented VPS infrastructure to compromised SOHO routers and consumer edge devices, while also abusing legitimate cloud services for covert command-and-control. The report says this infrastructure peaked in December 2025 at more than 18,000 unique IP addresses across 120 countries, affecting about 200 organizations and 5,000 consumer devices.
Google Cloud's Mandiant published a blog report titled "APT28 Malware | Russia's Cyber Espionage Operations Report," providing analysis of APT28 and its malware in the context of Russian cyber espionage activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.sekoia.io
Open sourcemandiant.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.