APT28 is a Russian state-sponsored cyber espionage threat actor widely associated with the GRU, specifically military unit 26165. It is one of the most established Russian intrusion sets and is commonly tracked under aliases including Fancy Bear, Sednit, Sofacy, Forest Blizzard, BlueDelta, and FrozenLake. The group has been active since at least 2004 and is known for long-running intelligence collection operations aligned with Russian strategic and military interests. APT28 primarily targets government, diplomatic, military, and defense organizations, with a strong emphasis on Ukraine and other Eastern European states, as well as NATO member countries and European public-sector entities. Reported victimology also includes research organizations, think tanks, and critical infrastructure-related entities. Operations attributed to the group have included campaigns against French ministries and defense-related organizations, Ukrainian military personnel, and government and defense email accounts across Eastern Europe. The actor is notable for exploiting webmail platforms to steal data from targeted accounts. In Operation RoundPress, APT28 exploited cross-site scripting vulnerabilities in Roundcube, MDaemon, Zimbra, and attempted exploitation of Horde to execute malicious JavaScript in victims’ browser sessions after a target opened a spearphishing email in a vulnerable webmail portal. These payloads harvested mailbox contents, contacts, login history, credentials, and in some cases information sufficient to bypass two-factor authentication or establish persistent access. The group has also exploited zero-day vulnerabilities in webmail software, including CVE-2024-11182 in MDaemon. APT28 continues to evolve its tooling. Recent operations have used PROMPTSTEAL, also known as LAMEHUG, a data-mining malware that queries a large language model during execution to generate host- and file-collection commands dynamically before exfiltration. The group has also been linked to NotDoor, also known as GONEPOSTAL, an Outlook VBA backdoor capable of command execution, file upload, and data theft, and to BeardShell, a C++ backdoor used in espionage operations against Ukrainian military personnel. In that campaign, APT28 used weaponized Signal conversations, malicious Office documents, COM hijacking, steganographic payload delivery via image files, customized Covenant components, and cloud services for command-and-control routing. APT28 consistently relies on spearphishing, exploitation of internet-facing services, credential theft, tailored malware, and post-compromise collection focused on sensitive communications and operational data. Its tradecraft reflects a mature intelligence service capability with sustained emphasis on reconnaissance, initial access, persistence, defense evasion, and exfiltration in support of Russian espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28 is deploying AI-enabled malware (PROMPTSTEAL) that leverages LLMs in live operations to generate commands for data harvesting and exfiltration, marking a shift to AI-assisted cyber espionage.
APT28 is leveraging AI-powered malware, specifically PROMPTSTEAL, to dynamically generate and execute system and file collection commands during live operations, enabling adaptive data exfiltration and evasion.
APT28 is conducting data-mining operations using AI-powered malware (PromptSteal) that leverages LLMs to generate commands dynamically during attacks. The malware is being used against Ukraine and is being actively developed to improve obfuscation and command-and-control methods.
APT28 has been observed leveraging LLM-enabled malware in campaigns such as LameHug and PROMPTSTEAL, embedding Large Language Model capabilities directly into malicious payloads to generate code at runtime and evade traditional detection methods.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.