Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
espionage
RussiaThreat Actor
Active Threat
APT28
148
IOCs Tracked
21
Intel Reports
Associated IOCs50 total
IP14
104.194.159.15031.57.243.15438.146.28.7595.179.213.045.77.31.21062.164.177.23045.93.20.141193.222.99.21291.202.233.20645.11.89.19193.35.17.1262.60.131.16145.32.144.255185.102.115.27Domain25
owa-ms365.com2026-08-02High
webhook.site2026-09-05High
m365-owa.com2026-08-02High
ms365-device.com2026-08-02High
ms365-live.com2026-08-02High
temp.sh2026-07-10High
birdrepgo.com2026-06-03High
guypinions.com2026-06-03High
customblindinstall.com2026-06-03High
safe-dns.it.com2026-06-03High
admin-activitycheck.com2026-06-03High
acconthelpdesk.com2026-06-03High
traderslinkfx.com2026-06-03High
cdncheck.it.com2026-06-03High
valetfortesla.com2026-06-03High
vipbirdrank.com2026-06-03High
cryptoinfnews.com2026-06-03High
macosxappstore.com2026-06-03High
appmacintosh.com2026-06-03High
mac-os-helper.com2026-06-03High
nowbirdrank.com2026-06-03High
birdreplab.com2026-06-03High
thepulseactivity.com2026-06-03High
appsmacosx.com2026-06-03High
deinhealthcoach.com2026-06-03High
URL5
http://169.40.135.35/dctrprraclus.zip2026-06-02High
http://169.40.135.35/dctrpr/slippersuppity.hta2026-06-02High
http://webhook.site/62114596-33f5-47fb-9012-0223529e5a13/docopened.jpg2026-08-28High
http://169.40.135.35/dctrpr/agentdiesel.hta2026-06-02High
http://169.40.135.35/dctrpr/*.hta2026-06-02High
MD51
b077401fe3d9642345d4c3deafa60aa52026-07-08High
SHA2562
4d4aec6120290e21778c1b14c94aa6ebff3b0816fb6798495dc2eae165db45662026-08-10High
b0f9f0a34ccab1337fbcca24b4f894de8d6d3a6f5db2e0463e2320215e4262e4CVE3
CVE-2026-240612026-07-01High
CVE-2026-201272026-07-24High
CVE-2026-13402026-08-26High
Related Reports21 total
Weekly Cybersecurity Newsletter — Top 50 Cybersecurity Stories of the Week
Cyber PressSep 6, 2026
Russian APT28-Linked Hackers Deploy HOOKEDGE Backdoor in European Espionage Attacks
Cyber PressSep 5, 2026
APT28 HOOKEDGE Backdoor Abuses Microsoft Edge and webhook.site for C2 and Data Exfiltration
Cyber PressAug 28, 2026
NSFOCUS Monthly APT Insights – April 2026
NSFOCUS Security LabsAug 13, 2026
Cyber Conflict Briefing Q2 2026
DCSO CyTec BlogAug 3, 2026
The Branding and Attribution Behind Cybercrime
Check Point BlogJul 27, 2026
Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing
Cyber PressJul 24, 2026
Explorer COM Hijacking Attack Loads Shellcode From AES-Encrypted Steganographic PNG
Cyber PressJul 8, 2026
APT28 Weaponizes Outlook Zero-Click Flaw to Steal Net-NTLMv2 Hashes From NATO Targets
Cyber PressJun 12, 2026
APT28, an evolution of tradecraft
Sekoia BlogJun 11, 2026
ClickFix Campaigns Targeting Windows and macOS
Recorded Future BlogMar 25, 2026
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
Recorded Future BlogMar 12, 2026
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
Recorded Future BlogFeb 24, 2026
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
Microsoft Threat IntelligenceApr 7, 2026
APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign)
Synaptic SystemsFeb 3, 2026
UAC-0184: From HTA to a Signed Network Stack
Synaptic SystemsMay 18, 2026
From APT28 to RePythonNET: automating .NET malware analysis
Sekoia BlogApr 16, 2026
NSFOCUS Monthly APT Insights – March 2026
NSFOCUS Security LabsMay 28, 2026
Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure
Lab52Feb 13, 2026
Cyber Conflict Briefing Q3 2025
DCSO CyTec BlogNov 18, 2025
Cyber Conflict Briefing Q4 2025
DCSO CyTec BlogFeb 13, 2026
Threat Profile
Motivationespionage
Origin
Russia
Last seenSep 2026
IOCs tracked148