APT28 is a Russian state-sponsored cyber espionage and information operations threat actor widely attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), specifically Unit 26165. It is one of the most extensively tracked Russian intrusion sets and is commonly associated with long-running espionage, credential theft, influence operations, and selective disruptive activity in support of Russian strategic and military objectives. APT28 is widely known under numerous aliases, including Fancy Bear, Sofacy, Sednit, STRONTIUM, Forest Blizzard, Pawn Storm, BlueDelta, Fighting Ursa, Iron Twilight, Swallowtail, Tsar Team, UAC-0001, and UAC-0028. Some reporting has used Forest Blizzard as the primary Microsoft designation for this actor. The alias set in circulation is noisy and sometimes conflated with other Russian actors; high-confidence attribution consistently centers on APT28, Fancy Bear, Sednit, Sofacy, STRONTIUM, and GRU Unit 26165. The group primarily targets government, military, defense-industrial, diplomatic, political, media, telecommunications, energy, and critical infrastructure entities, with a sustained emphasis on Ukraine, NATO member states, Europe, and North America. It has also targeted anti-doping organizations, international institutions, and election-related entities. Its operations are typically aligned with intelligence collection requirements, battlefield or geopolitical priorities, and broader Russian influence objectives. APT28 is known for combining traditional cyber espionage with active measures. Its operations have included spearphishing, credential harvesting, exploitation of public-facing applications and edge devices, malware deployment, abuse of valid accounts, adversary-in-the-middle collection, false personas, hack-and-leak activity, and amplification of stolen material for political or reputational effect. Public reporting has linked the group to campaigns involving theft of emails and documents, manipulated or selective disclosures, and covert support to information operations. Observed tradecraft includes phishing attachments and links, webmail and collaboration-platform exploitation, credential and session-token theft, DNS manipulation on small office and home office routers, and use of compromised edge infrastructure to intercept authentication flows. The actor has also been associated with exploitation of routers and network devices to gain footholds, support adversary-in-the-middle operations, and harvest credentials from remote workers and other targets using unmanaged or weakly managed network infrastructure. APT28 has historically used a broad malware ecosystem. Families and tooling associated with the group include X-Agent, X-Tunnel, Zebrocy, and more recent tooling such as PixyNetLoader and LameHug. Reported capabilities include persistence through COM hijacking or scheduled execution, stealthy payload delivery, tunneling, cloud-based command and control, steganographic configuration or payload concealment, and document collection. Zebrocy has long been treated as a notable malware family associated with the actor, although malware overlap alone is not sufficient for attribution in every case. The group has also been observed adopting contemporary delivery and evasion methods, including use of legitimate services and cloud platforms for command and control, living-off-the-land execution chains, and social-engineering techniques such as ClickFix-style user-assisted execution. Reporting further indicates use of utilities such as mshta and regsvr32 for proxy execution and staged payload delivery. APT28 is best understood as a GRU espionage actor that also supports broader Russian hybrid operations. In contrast to actors focused purely on long-term clandestine collection, APT28 has repeatedly demonstrated willingness to operationalize stolen information, create deceptive personas, and integrate cyber intrusion with influence and reputational attacks. This combination of espionage, credential theft, malware-enabled access, and information operations remains a defining characteristic of the group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
38 CVEs this actor has used in observed campaigns. 38 of them exploited in the wild.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
Leveraging a network scan we ran in February 2022, we found the server 45.138.87[.]250 / ceriossl[.]info... mentioned in a Qianxin blogpost describing a campaign abusing CVE-2023-23397 that attributed it to Sednit.
These attacks began with a phishing email, purporting to be from Ukraine's hydro-meteorological center, that contained a weaponized LNK file to exploit another vulnerability, CVE-2026-21513. By chaining CVE-2026-21513 with CVE-2026-21510, the Russian spies bypassed Microsoft security features including Defender SmartScreen and remotely executed malicious code on victims' computers.
GooseEgg weaponises CVE-2022-38028 in the Windows Print Spooler service to obtain SYSTEM-level execution.
33 more CVEs tied to this actor tracked in Mallory.
531 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only in passing as part of unrelated promotional/latest insights content about Russian cyber espionage targeting SOHO routers for adversary-in-the-middle attacks.
Russian GRU-linked APT conducting campaigns such as PRISMEX, using cloud C2, spear-phishing, mshta.exe delivery of HATVIBE, and exploitation of Roundcube via XSS and IMAP injection.
Referenced as one of several state-backed groups incorporating ClickFix into existing infection chains.
Conducts military intelligence collection, credential theft, espionage, hack-and-leak operations, and influence support by converting stolen information into political, psychological, and reputational effects.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.