Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Dark Web Profile: APT28
Jan 20, 2026
14 Mins Read
Jun 03, 2026
Moon

Dark Web Profile: APT28

APT28 is one of the most tracked state-linked intrusion sets because its activity often aligns with major geopolitical events and long-running espionage goals. Also known as Fancy Bear and Sofacy, the group is widely assessed to operate on behalf of Russia’s military intelligence agency (GRU), and has been linked to Unit 26165.

Public attributions through 2024 and 2025 kept the APT group in focus, including campaigns targeting European entities and organizations connected to Ukraine and Western support efforts. In 2025, reports of new malware and updated techniques tied to account access reinforced a consistent theme: APT28 prioritizes intelligence collection and persistence over loud, destructive attacks.

Who Is APT28?

APT28 is a long-running cyber espionage group widely attributed to Russia’s military intelligence service, the GRU. Public indictments, government advisories, and private-sector research have repeatedly linked the group to GRU Unit 26165, placing APT28 among the most clearly attributed state-sponsored threat actors active today.

Threat actor card of APT28

Threat actor card of APT28

Activity associated with the group has been observed since at least the mid-2000s, with operations spanning Europe, North America, and regions tied to Russia’s strategic interests.

The group is known under multiple aliases, including Fancy Bear, Sofacy, Sednit, Pawn Storm, STRONTIUM, BlueDelta, and Forest Blizzard. While the names differ by vendor or government source, reporting consistently points to the same core intrusion set and operational goals.

APT28’s campaigns are typically intelligence-driven, focusing on access to government communications, diplomatic correspondence, military planning, and policy-related information rather than financial gain.

Over the years, APT28 has been linked to several high-profile incidents, including intrusions affecting political organizations, international institutions, media outlets, and government bodies. Its continued activity through 2024 and 2025, particularly in Europe and Ukraine-related contexts, shows that the group remains operational, adaptive, and closely aligned with broader Russian geopolitical objectives.

What Are APT28’s Targets?

APT28 consistently targets countries and sectors that align with Russia’s military, political, and intelligence priorities, with a strong focus on NATO members and organizations involved in supporting Ukraine. Its operations are heavily concentrated in Europe and North America, while Ukraine remains one of the most persistently targeted environments, with hundreds of victims identified across government, research, and critical services since 2021.

By country, APT28 has repeatedly targeted the United States, the United Kingdom, Germany, France, Poland, Canada, and Norway, alongside sustained campaigns in Ukraine. Activity has also been observed in Georgia, Kazakhstan, and other parts of Central Asia and Eastern Europe, reflecting both regional expansion and continued interest in NATO’s eastern flank and neighboring states.

Top targeted countries by APT28

Top targeted countries by APT28

By sector, the group prioritizes intelligence-rich environments rather than financially motivated targets. Government institutions, diplomatic bodies, defense and military organizations, and NATO-linked entities remain core objectives. In parallel, APT28 has targeted energy providers, aerospace and aviation firms, transportation and logistics companies, and technology service providers that support defense operations or international aid efforts. Media organizations, journalists, universities, and research institutions have also been targeted, particularly where access could yield political insight or influence.

Top targeted industries by APT28

Top targeted industries by APT28

Overall, APT28’s targeting reflects a clear intelligence-collection mandate: access information, communications, and operational insight that support state decision-making, military planning, and geopolitical influence.

What Are APT28’s Techniques?

APT28 employs a full-spectrum intrusion lifecycle, combining proven espionage tradecraft with selective technical innovation. Its techniques map closely to the classic attack cycle, with each phase designed to minimize detection while enabling long-term access to sensitive information.

Initial Access

APT28 commonly gains entry through targeted spear phishing campaigns, malicious links or attachments, and exploitation of public-facing applications, particularly webmail and edge infrastructure. The group has repeatedly abused trusted relationships and compromised accounts, including cloud and email credentials, to bypass perimeter defenses and appear as legitimate users.

Execution

Once initial access is achieved, APT28 frequently relies on built-in system utilities to execute commands. PowerShell, the Windows command shell, and trusted binaries such as rundll32 are commonly used to run payloads and scripts while blending in with normal system activity. In browser- or email-based attacks, client-side exploitation allows code to execute as soon as malicious content is rendered.

Persistence and Privilege Escalation

To maintain access, APT28 has been observed modifying logon scripts, registry run keys, scheduled tasks, and COM objects. In some campaigns, persistence is lightweight or temporary, reflecting intelligence-driven objectives rather than long-term monetization. Privilege escalation may involve exploiting vulnerabilities or abusing access tokens and valid accounts to expand control within the environment.

Credential Access

Credential theft is a central focus of APT28 operations. Techniques include password spraying, dumping credentials from memory and directory services, keylogging, network sniffing, and harvesting authentication tokens. Email platforms and cloud services are frequent targets, as access to communications often provides immediate intelligence value.

Discovery and Lateral Movement

After establishing a foothold, the group conducts targeted discovery to map users, systems, processes, and network configurations. Lateral movement is typically achieved through remote services such as RDP or SMB, exploitation of remote services, or reuse of compromised credentials, allowing the attackers to pivot toward higher-value systems.

Command and Control

APT28 favors command-and-control channels that resemble legitimate traffic. Communications often occur over standard web and mail protocols, encrypted channels, and cloud-based or proxy infrastructure. The use of common services and layered proxies helps obscure malicious traffic and complicates network-level detection.

Collection and Exfiltration

Data collection focuses on emails, documents, shared repositories, screenshots, and system information. Collected data is staged locally or remotely, often compressed and obfuscated before exfiltration. Exfiltration typically occurs over web services or alternative encrypted channels in a controlled, low-volume manner to avoid detection.

Defense Evasion and Impact

Throughout the intrusion, APT28 actively removes indicators of compromise, clears logs, deletes artifacts, and disguises malicious files as legitimate resources. While disruption is not the primary goal, the group has demonstrated the capability to wipe disks or degrade systems when aligned with broader operational objectives.

Together, these techniques form a disciplined espionage workflow, optimized for stealth, adaptability, and sustained intelligence collection rather than rapid or destructive outcomes.

What Are the Campaigns Related to APT28?

APT28 has a long track record of espionage operations that repeatedly surfaced around elections, military priorities, and government decision-making. Below are several campaigns that helped shape how defenders track the group today.

Threat actor details of APT28, SOCRadar Cyber Threat Intelligence module 

Threat actor details of APT28, SOCRadar Cyber Threat Intelligence module

LAMEHUG AI-Assisted Malware Deployment (2025)

In 2025, reporting from CERT-UA and security researchers revealed LAMEHUG, a malware framework that integrated Large Language Model (LLM) capabilities into active operations. LAMEHUG enabled dynamic, host-specific command generation via a cloud-based AI service, allowing operators to adjust reconnaissance and collection in real time.

The infection chain began with phishing emails delivering ZIP archives with a PyInstaller-packed executable disguised as a document, and early deployment focused on Ukrainian government targets, consistent with prior observations that APT28 often trials new tooling in Ukraine first.

Phishing email sent from a hijacked official account, delivering LameHug malware (CERT-UA)

Phishing email sent from a hijacked official account, delivering LameHug malware (CERT-UA)

Credential and Token Theft Against Email and Cloud Accounts (2024-2025)

Public reporting in late 2025 linked APT28 to a long-running credential harvesting campaign targeting UKR.net users, using phishing emails that routed victims to fake login pages hosted on legitimate services and aiming to capture both credentials and 2FA codes. Separately, the UK NCSC attributed “AUTHENTIC ANTICS” malware to APT28, describing how it prompted for Microsoft cloud logins and captured credentials and OAuth tokens to maintain access while blending into normal account activity.

Credential harvesting login page impersonating UKR[.]net

Credential harvesting login page impersonating UKR[.]net

Western Logistics and Technology Targets Supporting Aid to Ukraine (Since 2022)

A May 2025 joint advisory warned of a sustained GRU-linked espionage campaign targeting logistics entities and technology companies involved in coordinating, transporting, or delivering assistance to Ukraine. The guidance framed the activity as intelligence collection oriented, with targeting expanding across supply-chain connected organizations and using a mix of phishing, credential access, and exploitation paths depending on the victim environment.

Targeting of French Entities Using the APT28 Intrusion Set (2021-2024)

France publicly attributed a series of intrusions affecting French interests to APT28, alongside a technical write-up from France’s CERT describing campaigns observed since 2021. The report highlighted recurring entry paths such as phishing, exploitation of vulnerabilities (including CVE-2023-23397), and brute-force activity against webmail, plus heavy use of outsourced infrastructure like rented servers, VPN services, and free hosting to stay flexible and harder to track.

Cisco Routers Reconnaissance and Malware Deployment (2021)

A joint U.S. and UK advisory described APT28 activity against poorly maintained Cisco routers in 2021, where attackers abused SNMP access and exploited CVE-2017-6742. The advisory reported reconnaissance against routers globally and noted roughly 250 Ukrainian victims, with follow-on malware deployment on some devices to collect device and network details and exfiltrate them.

CVE-2017-6742 (SOCRadar Vulnerability Intelligence)

CVE-2017-6742 (SOCRadar Vulnerability Intelligence)

U.S. Political Organizations Compromise (2016)

In 2016, U.S. authorities linked GRU Unit 26165 to intrusions targeting political organizations such as the DNC and DCCC. Public reporting and later U.S. indictments described credential theft and network access used to collect emails and documents, followed by staged leak activity through personas and distribution sites.

German Bundestag Intrusion (2015)

APT28 activity was attributed to the 2015 attack on Germany’s parliament, which resulted in significant data theft and disruption of email accounts belonging to MPs and senior officials. The incident later drove public attributions and sanctions that explicitly referenced GRU Unit 26165 as responsible.

What Are the Mitigation Tactics Against APT28?

APT28 focuses on credential access, covert persistence, and long-term intelligence collection rather than rapid disruption. Defenses should prioritize identity protection, phishing resistance, and visibility into low-noise activity.

  • Block Initial Access: Limit exposure of VPNs, web apps, and remote services; enforce MFA; rapidly patch internet-facing infrastructure and network devices.
  • Protect Identities: Use strong, unique credentials; disable unused accounts; monitor delegated permissions and abnormal authentication activity across cloud and email platforms.
  • Harden Email & Phishing Defenses: Deploy advanced email filtering, attachment sandboxing, and user awareness training focused on targeted spearphishing.
  • Restrict Native Tool Abuse: Monitor and constrain PowerShell, command-line tools, and trusted binaries commonly abused for execution and evasion.
  • Detect Persistence Early: Watch for registry changes, startup scripts, COM hijacking, scheduled tasks, and unauthorized service creation.
  • Limit Lateral Movement: Segment networks; restrict RDP and SMB access; apply just-in-time administration and audit remote service usage.
  • Monitor Command-and-Control: Inspect outbound web traffic, proxy usage, and encrypted channels for low-profile C2 patterns.
  • Protect Sensitive Data: Control access to SharePoint, file servers, and email repositories; alert on bulk or automated data access.
  • Apply Threat Intelligence: Track APT28 infrastructure, phishing themes, and IoCs; monitor open and dark web sources for exposed credentials or targeting indicators.
  • Validate Readiness: Run threat-hunting and purple-team exercises mapped to APT28’s MITRE ATT&CK techniques.

How Can SOCRadar Help?

APT28 is a long-running espionage actor known for sustained access operations rather than loud, monetized attacks. Instead of rapid campaigns, the group has historically relied on credential harvesting, targeted phishing, exploit-based initial access, and custom malware to quietly collect intelligence over extended periods. Its operations tend to evolve through changes in infrastructure, tooling, and delivery methods, while the underlying tradecraft remains consistent.

Defending against this type of actor requires visibility into exposure and early indicators of compromise, not just perimeter controls. Organizations need to understand whether their credentials, domains, or internal references have been exposed, and whether infrastructure commonly abused during reconnaissance or initial access remains reachable.

SOCRadar supports this by combining threat actor intelligence with real-world exposure monitoring and continuous data collection from open, deep, and Dark Web sources.

Teams can start with a Free Dark Web Report from SOCRadar Labs to identify whether corporate domains, email addresses, or credentials have appeared in environments that could enable follow-on access.

  • Dark Web Monitoring helps surface leaked credentials, internal documents, or operational references that could be leveraged in phishing, account takeover, or lateral movement activity associated with APT28-style campaigns.
  • Threat Intelligence Feeds deliver regularly updated indicators, infrastructure patterns, and contextual insights tied to known APT28 techniques, enabling security teams to enrich detections and prioritize alerts based on active threat behavior.
  • Attack Surface Management assists in identifying exposed services, remote access points, and misconfigurations that may be targeted during reconnaissance or exploitation phases observed in past APT28 operations.
  • Digital Risk Protection supports the detection of phishing infrastructure, spoofed domains, and impersonation attempts that align with credential-harvesting and access-focused campaigns.

SOCRadar’s Dark Web Monitoring

SOCRadar’s Dark Web Monitoring

By correlating threat actor intelligence with exposure data and early warning signals, SOCRadar helps organizations reduce blind spots and respond to APT28-like activity with informed, timely decisions.

What Are the MITRE ATT&CK TTPs of APT28?

Tactic Technique ID Technique Name
Initial Access T1189 Drive-by Compromise
T1190 Exploit Public-Facing Application
T1566.001 Phishing: Spearphishing Attachment
T1598.003 Spearphishing Link
T1204.001 User Execution: Malicious Link
T1204.002 User Execution: Malicious File
T1133 External Remote Services
T1199 Trusted Relationship
T1586.002 Compromise Accounts: Email Accounts
T1584.008 Compromise Infrastructure: Network Devices
T1078 Valid Accounts
T1078.004 Valid Accounts: Cloud Accounts
Execution T1059.001 Command and Scripting Interpreter: PowerShell
T1059.003 Command and Scripting Interpreter: Windows Command Shell
T1203 Exploitation for Client Execution
T1218.011 System Binary Proxy Execution: Rundll32
T1137.002 Office Application Startup: Office Test
T1559.002 Inter-Process Communication: Dynamic Data Exchange
T1221 Template Injection
Persistence T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
T1037.001 Boot or Logon Initialization Scripts: Logon Script
T1098.002 Account Manipulation: Additional Email Delegate Permissions
T1546.015 Event Triggered Execution: Component Object Model Hijacking
T1505.003 Server Software Component: Web Shell
T1542.003 Pre-OS Boot: Bootkit
T1014 Rootkit
Privilege Escalation T1068 Exploitation for Privilege Escalation
T1134.001 Access Token Manipulation: Token Impersonation/Theft
Defense Evasion T1211 Exploitation for Defense Evasion
T1562.004 Impair Defenses: Disable or Modify System Firewall
T1070.001 Indicator Removal: Clear Windows Event Logs
T1070.004 Indicator Removal: File Deletion
T1070.006 Indicator Removal: Timestomp
T1564.001 Hide Artifacts: Hidden Files and Directories
T1564.003 Hide Artifacts: Hidden Window
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
T1140 Deobfuscate/Decode Files or Information
T1006 Direct Volume Access
T1036 Masquerading
T1036.005 Masquerading: Match Legitimate Resource Name or Location
T1001.001 Data Obfuscation: Junk Data
Credential Access T1110 Brute Force
T1110.001 Brute Force: Password Guessing
T1110.003 Brute Force: Password Spraying
T1003 OS Credential Dumping
T1003.001 OS Credential Dumping: LSASS Memory
T1003.002 OS Credential Dumping: Security Account Manager
T1003.003 OS Credential Dumping: NTDS
T1056.001 Input Capture: Keylogging
T1040 Network Sniffing
T1557.004 Adversary-in-the-Middle: Evil Twin
T1528 Steal Application Access Token
T1550.001 Use Alternate Authentication Material: Application Access Token
T1550.002 Use Alternate Authentication Material: Pass the Hash
T1589.001 Gather Victim Identity Information: Credentials
Discovery T1083 File and Directory Discovery
T1057 Process Discovery
T1120 Peripheral Device Discovery
T1016.002 System Network Configuration Discovery: Wi-Fi Discovery
T1596 Search Open Technical Databases
T1591 Gather Victim Org Information
T1669 Wi-Fi Networks
Lateral Movement T1210 Exploitation of Remote Services
T1021.001 Remote Services: Remote Desktop Protocol
T1021.002 Remote Services: SMB/Windows Admin Shares
T1091 Replication Through Removable Media
Collection T1119 Automated Collection
T1213 Data from Information Repositories
T1213.002 Data from Information Repositories: Sharepoint
T1005 Data from Local System
T1039 Data from Network Shared Drive
T1025 Data from Removable Media
T1113 Screen Capture
T1114.002 Email Collection: Remote Email Collection
T1560 Archive Collected Data
T1560.001 Archive via Utility
T1074.001 Data Staged: Local Data Staging
T1074.002 Data Staged: Remote Data Staging
Command and Control T1071.001 Application Layer Protocol: Web Protocols
T1071.003 Application Layer Protocol: Mail Protocols
T1102.002 Web Service: Bidirectional Communication
T1090.001 Proxy: Internal Proxy
T1090.002 Proxy: External Proxy
T1090.003 Proxy: Multi-hop Proxy
T1573.001 Encrypted Channel: Symmetric Cryptography
T1105 Ingress Tool Transfer
T1092 Communication Through Removable Media
Exfiltration T1048.002 Exfiltration Over Alternative Protocol
T1567 Exfiltration Over Web Service
T1030 Data Transfer Size Limits
Impact T1561.001 Disk Wipe: Disk Content Wipe
T1498 Network Denial of Service
Reconnaissance T1595.002 Active Scanning: Vulnerability Scanning
T1598 Phishing for Information
Resource Development T1583.001 Acquire Infrastructure: Domains
T1583.003 Acquire Infrastructure: Virtual Private Server
T1583.006 Acquire Infrastructure: Web Services
T1588.002 Obtain Capabilities: Tool