APT28 is a Russia-linked state-sponsored threat actor widely tracked under aliases including TA422 and Sofacy. The group is associated with espionage operations aligned with Russian strategic interests and has repeatedly targeted Ukrainian government organizations as well as European defense, transportation, diplomatic, and broader defense-industry entities. The actor is known for targeted phishing and document-based intrusion activity, including rapid weaponization of newly disclosed vulnerabilities. In 2026, APT28 was observed exploiting Microsoft Office RTF/OLE code-execution vulnerabilities within a day of public disclosure against Ukrainian and European targets, demonstrating a high operational tempo and the ability to incorporate public proof-of-concept material quickly. The group has also been linked to exploitation of Windows vulnerabilities in campaigns against Ukraine and EU member states. APT28 employs social engineering extensively for initial access and execution. Observed tradecraft includes phishing emails delivering malicious documents, links masquerading as trusted collaboration content, and ClickFix-style lures that trick victims into manually executing PowerShell commands. In one such campaign targeting Ukrainian entities, the actor used a fake spreadsheet-themed lure and reCAPTCHA flow to induce command execution, then established access using an SSH tunnel and offensive tooling. Reporting has also linked APT28 activity to follow-on deployment of implants including NotDoor and Covenant Grunt in some exploitation chains. The group’s operations reflect opportunistic adoption of effective techniques without fundamentally changing its espionage mission. Its tradecraft includes credential theft, malware delivery, command execution through PowerShell, use of tunneling and post-exploitation frameworks, and abuse of cloud services for command-and-control support. APT28 remains one of the most active Russian espionage actors and is notable for combining targeted spearphishing, fast exploit operationalization, and adaptable execution methods against government and strategic-sector victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
The security vulnerability in question is CVE-2023-23397 (CVSS score: 9.8), a critical privilege escalation bug that could allow an adversary to access a user's Net-NTLMv2 hash that could then be used to conduct a relay attack against another service to authenticate as the user. It was patched by Microsoft in March 2023.
In recent months, it has also been connected to attacks on various organizations in France and Ukraine as well as the abuse of the WinRAR flaw (CVE-2023-38831) to steal browser login data using a PowerShell script named IRONJAW.
CVE-2026-21510 — Windows Shell Protection Mechanism Failure In two separate campaigns observed by Proofpoint in March and April 2026, DPRK-aligned threat actor TA406 (Opal Sleet) chained CVE-2026-21509 and CVE-2026-21510 within a single attack sequence... invoked CVE-2026-21510 to bypass Windows Shell security controls and execute a DLL payload.
The flaw was exploited as a zero-day alongside CVE-2026-21513 by TA422 in attacks targeting Ukraine and EU member states beginning in late 2025.
1 more CVE tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of a threat actor opportunistically exploiting public proof-of-concept code for network-facing vulnerabilities in 2026; not specifically tied to exploitation of CVE-2026-42055 in this content.
Mentioned as an example of rapid weaponization of newly disclosed CVEs, not as an actor involved in the Sitefinity vulnerability.
Mentioned as an active 2026 threat actor and as an example of rapid weaponization, exploiting a disclosed CVE within 24 hours.
Rapidly weaponized newly disclosed Microsoft Office and Windows vulnerabilities in targeted spear-phishing campaigns against Ukrainian government agencies and European defense, transportation, diplomatic, and EU member state targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.