NEARTWIST is an activity cluster linked with moderate confidence to APT28. Reported activity includes the use of commercial VPN infrastructure to obscure operator origin during post-compromise access, specifically logging into web shells through VPN services. The cluster is associated with operations against Ukraine. Based on the observed behavior, NEARTWIST demonstrates post-exploitation tradecraft and defense-evasion measures intended to blend malicious access into legitimate remote-access patterns and complicate attribution. Given the stated linkage, NEARTWIST may represent an operational cluster associated with the broader APT28 ecosystem rather than a fully distinct intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.