APT28 is a Russian state-sponsored cyber-espionage threat actor assessed to operate for the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). It is publicly associated with the GRU’s 85th Main Special Service Center, Military Unit 26165. Widely used aliases include Fancy Bear, Sofacy, STRONTIUM, Forest Blizzard, Pawn Storm, Sednit, BlueDelta, Fighting Ursa, and Swallowtail. APT28 primarily conducts intelligence collection against government, diplomatic, military, defense, political, and policy-related targets. It has targeted Ukraine and the United States historically, and conducted campaigns against government, diplomatic, and defense-manufacturing organizations in Romania, Spain, and Türkiye during late 2025 through early 2026. The group commonly obtains access through spearphishing and malicious documents, including macro-enabled Microsoft Word lures. In the 2025–2026 activity attributed to BlueDelta, it deployed the HOOKEDGE Windows backdoor, assessed as an evolution of the group’s earlier HEADLACE implant. The malware established scheduled-task persistence, obtained tasking through public webhook infrastructure using Microsoft Edge, executed received commands, and exfiltrated command output. Operators used document- and email-open tracking, distinct collection tiers for higher-value victims, altered beacon intervals to hinder sandbox analysis, and deleted temporary artifacts to reduce forensic visibility. APT28 has also been associated with credential dumping using Mimikatz, exploitation of vulnerable network devices, reconnaissance, and the repurposing of compromised-device infrastructure to deploy malware. Its operations are assessed to support Russian military and state intelligence requirements.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
51 malware families attributed to this actor across reporting.
46 additional families tracked in Mallory.
38 CVEs this actor has used in observed campaigns. 38 of them exploited in the wild.
Pawn Storm’s campaign in late January 2026 exploited the Microsoft Office vulnerability CVE-2026-21509 to target government, military, and critical infrastructure entities across Central and Eastern Europe. The PRISMEX campaign’s initial access vector relies on the weaponization of CVE-2026-21509, a security feature bypass vulnerability in the Microsoft Office Object Linking and Embedding (OLE) mechanism.
Other campaigns have entailed the exploitation of security flaws in Microsoft Outlook (CVE-2023-23397, CVSS score: 9.8) to plunder NT LAN Manager (NTLM) v2 hashes, raising the possibility that the threat actor may leverage other weaknesses to exfiltrate NTLMv2 hashes for use in relay attacks.
A critical vulnerability in Synacor Zimbra Collaboration Suite, tracked as CVE-2025-66376, has been exploited by Russian state-sponsored threat actors in targeted attacks against Western governments and Ukraine. The flaw is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI, where a malicious HTML email abuses CSS @import directives to execute arbitrary JavaScript when opened in a vulnerable webmail session.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
CVE-2026-21513 resides in the logic responsible for handling hyperlink navigation within ieframe.dll (Internet Explorer frame). CVE-2026-21513 was exploited as a zero-day vulnerability. The exploit sample was first submitted to VirusTotal on January 30, 2026. This was 11 days before Microsoft released the patch on February 10, 2026.
33 more CVEs tied to this actor tracked in Mallory.
1,506 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A GRU-linked cyber-espionage group whose personnel pipeline is connected to Bauman University's Department No. 4. The article notes that Unit 26165, associated with APT28, was involved in Russian interference in the 2016 U.S. presidential election.
Mentioned as a well-known Russian cyber entity in the context of the GRU's broader institutional cyber-force pipeline; no specific activity is described.
A GRU-linked espionage and reconnaissance group associated with Military Unit 26165. The content identifies senior unit leadership in the reported Department No. 4 oversight structure and describes the group as exploiting vulnerable Cisco routers and deploying Jaguar Tooth malware.
Mentioned as a familiar GRU-associated threat-actor brand in the context of Russia's broader institutional cyber personnel pipeline; no specific operation or TTP is attributed to it in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.