APT28 is a Russian state-linked cyber espionage threat actor widely tracked under aliases including Fancy Bear, Sofacy, Sednit, Pawn Storm, Strontium, Forest Blizzard, BlueDelta, Fighting Ursa, Tsar Team, Group 74, and Iron Twilight. The group is associated with long-running intelligence collection and influence-related operations aligned with Russian state interests, and is frequently linked by governments and industry to Russian military intelligence activity. APT28 has been implicated in operations against government, defense, diplomatic, political, and critical infrastructure targets, including activity directed at Ukraine and the United States. APT28 is known for spearphishing-led initial access, particularly malicious Microsoft Office attachments and macro-enabled documents, as well as the use of spoofed or lookalike infrastructure themed around organizations of geopolitical interest such as NATO and the OSCE. The group has also exploited Windows vulnerabilities, including zero-days, and has been associated with UEFI bootkit activity through LoJax. Its malware ecosystem has included families such as Zebrocy and CHOPSTICK, along with Delphi backdoors, staged downloaders, and modular implants that retrieve second-stage payloads from command-and-control infrastructure. Operationally, APT28 demonstrates mature post-compromise tradecraft. Reported behaviors include process discovery, PowerShell-based execution, staged payload delivery, screenshot capture, keylogging, collection of internal documents, and exfiltration of victim data. The group has used defense-evasion measures such as concealed PowerShell execution, hidden file attributes, payload decoding with built-in utilities, and deletion of files to cover tracks. Implants have used HTTP and HTTPS for command and control, and loaders have enumerated processes to identify suitable execution contexts. APT28 has been publicly tied to cyber espionage campaigns against Ukrainian state entities, including targeting of officials connected to Ukraine’s Asset Recovery and Management Agency. The group has also been associated with the compromise of U.S. political organizations during the 2016 election cycle. Across reporting, APT28 is consistently characterized as a highly capable Russian espionage actor focused on strategic intelligence collection, credential and document theft, and support to broader Russian information and geopolitical objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
36 CVEs this actor has used in observed campaigns. 36 of them exploited in the wild.
2026-02-04 ⋅ StrikeReady ⋅ APT28’s Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and Cloud C2 Infrastructure ... 2026-02-02 ⋅ Zscaler ⋅ APT28 Leverages CVE-2026-21509 in Operation Neusploit
Other campaigns have entailed the exploitation of security flaws in Microsoft Outlook (CVE-2023-23397, CVSS score: 9.8) to plunder NT LAN Manager (NTLM) v2 hashes, raising the possibility that the threat actor may leverage other weaknesses to exfiltrate NTLMv2 hashes for use in relay attacks.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
This ongoing analysis led to the discovery of another zero-day vulnerability utilized in the operation (CVE-2026-21513)... CVE-2026-21513 is another vulnerability within the Microsoft MSHTML framework, specifically located in the _AttemptShellExecuteForHlinkNavigate function of ieframe.dll, the core library of the Internet Explorer browser.
A critical vulnerability in Synacor Zimbra Collaboration Suite, tracked as CVE-2025-66376, has been exploited by Russian state-sponsored threat actors in targeted attacks against Western governments and Ukraine. The flaw is a stored cross-site scripting (XSS) vulnerability in Zimbra's Classic UI, where a malicious HTML email abuses CSS @import directives to execute arbitrary JavaScript when opened in a vulnerable webmail session.
31 more CVEs tied to this actor tracked in Mallory.
1,444 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed to a prior cyberespionage campaign targeting ARMA employees; mentioned as a suspected Russia-linked threat in historical context, not as the confirmed actor behind the latest incident.
Conducted 'Operation Neusploit' targeting Ukrainian defense institutions and allied nations, using zero-day vulnerabilities, geofencing, trojans, steganography, and spear-phishing as part of an expanded campaign against defense objectives.
Associated with the AI-enabled PROMPTSTEAL operation deployed in Ukraine.
Mentioned only in related content links, not part of the CaptiveCrunch campaign discussed in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.