APT28

☆ pin
MITRE G0007Also known as BlueDelta, Sednit, Unit 26165, Forest Blizzard, Pawn Storm, GruesomeLarch, Fighting Ursa, Fancy Bear, FancyBear, UAC-0001, Sofacy
Reports
24
First seen
Nov 22, 2024
Last seen
Jul 24, 2026
Motivation
Espionage, Geopolitical

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×3
Ukraine×3
Canada×1
United States×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×13T1190 Exploit Public-Facing Application ×13T1041 Exfiltration Over C2 Channel ×10T1059 Command and Scripting Interpreter ×6T1078 Valid Accounts ×6T1003 OS Credential Dumping ×6T1486 Data Encrypted for Impact ×6T1598 Phishing for Information ×5T1195 Supply Chain Compromise ×5T1110 Brute Force ×5T1021 Remote Services ×5T1071 Application Layer Protocol ×4

Indicators

cve ×58filename ×49domain ×40ip_v4 ×26url ×8email ×5registry_key ×4hash_sha256 ×3hash_sha1 ×2

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

Bleeping Computer
Critical

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News
Critical

US and allies warn of Russian critical infrastructure attacks

Bleeping Computer
High

Zimbra urges customers to patch critical web client XSS flaw

Bleeping Computer
High

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

The Hacker News
High

Canada's CSIS Used First Warrant to Remotely Clean Botnet-Infected Devices

The Hacker News
High

Threats to the 2026 FIFA World Cup: Physical Security, Cyber, and Influence Operations Risk Assessment

Recorded Future Insikt
High

ESET APT Activity Report Q4 2025–Q1 2026

ESET WeLiveSecurity
High

Ukraine reports Russia deploying AI-powered malware in cyberwar operations

The Record (Recorded Future News)
High

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

Palo Alto Unit 42
High

CERT-EU Cyber Brief April 2026 – Espionage, Supply-Chain Attacks, and Critical Infrastructure Threats

CERT-EU Threat Intel
Critical

Russia's GRU-Linked Forest Blizzard Harvests Microsoft OAuth Tokens via Router DNS Hijacking

KrebsOnSecurity
High

CERT-EU Cyber Brief March 2026 – Espionage, Supply-Chain Attacks, Iran Conflict Disruptions

CERT-EU Threat Intel
Critical

Threat Intelligence Report – 30 March: FBI Director Account Breach, Port Ransomware, Supply Chain Compromises

Check Point Research
Critical

Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities

Trend Micro Research
High

ClickFix Campaigns Targeting Windows and macOS: Five Distinct Clusters

Recorded Future Insikt
Critical

February 2026 CVE Landscape: 13 Critical Vulnerabilities, 43% Drop from January

Recorded Future Insikt
Critical

Sednit reloaded: Advanced implant team returns with BeardShell and Covenant

ESET WeLiveSecurity
High

CERT-EU Cyber Brief February 2026: APT28, China espionage, AI supply-chain attacks, Qilin ransomware

CERT-EU Threat Intel
Critical

Preparing for Russia's New Generation Warfare in NATO Territory

Recorded Future Insikt
Critical

January 2026 CVE Landscape: 23 Critical Vulnerabilities, APT28 Exploits Microsoft Office Zero-Day

Recorded Future Insikt
High

2025 Cloud Threat Hunting and Defense Landscape

Recorded Future Insikt
High

Cyber Brief December 2025: Espionage, Ransomware, and Infrastructure Attacks Across Europe and Beyond

CERT-EU Threat Intel
High

The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access

Volexity

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.