APT28, also known as Fancy Bear and tracked here as APT-C-20, is a well-known cyber espionage threat actor associated with Russia. The group is known for targeting government, diplomatic, and defense-related entities, particularly in contexts aligned with Russian strategic intelligence interests. In this activity cluster, the actor used a fileless intrusion chain centered on a malicious macro-enabled Microsoft Word lure with Eastern European defense-themed content. The operation employed layered defense evasion and in-memory execution. After macro execution, the malware dropped a malicious DLL and a seemingly benign PNG image, then established persistence through COM hijacking tied to Windows Explorer. The DLL loader validated its execution context, performed anti-analysis timing checks, extracted encrypted payload material hidden in image pixels using steganographic techniques, decrypted shellcode, and executed it entirely in memory. The shellcode then reflectively loaded an obfuscated C# backdoor. The backdoor gathered host and user context, generated a victim identifier, encrypted collected data, and communicated through cloud storage gateway infrastructure rather than a conventional dedicated command-and-control server. It also supported receipt and loading of additional attacker-supplied code, indicating flexible post-compromise capability. This tradecraft reflects emphasis on stealth, persistence, memory-resident execution, and evasion of conventional endpoint detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.