IOC Radar
espionageRURussiaThreat Actor
Active Threat

APT28

123
IOCs Tracked
11
Intel Reports
Associated IOCs50 total
Domain27
macosx-app.com
2026-06-03High
anthonydee.com
2026-06-03High
customblindinstall.com
2026-06-03High
cdncheck.it.com
2026-06-03High
nobovcs.com
2026-06-03High
helpdeskpulse.com
2026-06-03High
extracareliving.com
2026-06-03High
cryptoinfnews.com
2026-06-03High
mac-os-helper.com
2026-06-03High
safe-dns.it.com
2026-06-03High
admin-activitycheck.com
2026-06-03High
guypinions.com
2026-06-03High
yvngvualr.com
2026-06-03High
sign-in-op-token.com
2026-06-03High
macosxappstore.com
2026-06-03High
appmacintosh.com
2026-06-03High
nowbirdrank.com
2026-06-03High
birdreplab.com
2026-06-03High
thepulseactivity.com
2026-06-03High
appsmacosx.com
2026-06-03High
valetfortesla.com
2026-06-03High
traderslinkfx.com
2026-06-03High
deinhealthcoach.com
2026-06-03High
temp.sh
2026-06-03High
birdrepgo.com
2026-06-03High
acconthelpdesk.com
2026-06-03High
vipbirdrank.com
2026-06-03High
Related Reports11 total
ClickFix Campaigns Targeting Windows and macOS
Recorded Future BlogMar 25, 2026
132 IOC
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
Recorded Future BlogFeb 24, 2026
30 IOC
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
Recorded Future BlogMar 12, 2026
22 IOC
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
Microsoft Threat IntelligenceApr 7, 2026
UAC-0184: From HTA to a Signed Network Stack
Synaptic SystemsMay 18, 2026
14 IOC
APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign)
Synaptic SystemsFeb 3, 2026
6 IOC
From APT28 to RePythonNET: automating .NET malware analysis
Sekoia BlogApr 16, 2026
NSFOCUS Monthly APT Insights – March 2026
NSFOCUS Security LabsMay 28, 2026
1 IOC
Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure
Lab52Feb 13, 2026
Cyber Conflict Briefing Q3 2025
DCSO CyTec BlogNov 18, 2025
Cyber Conflict Briefing Q4 2025
DCSO CyTec BlogFeb 13, 2026
1 IOC
Threat Profile
Motivationespionage
OriginRURussia
Last seenJun 2026
IOCs tracked123