APT28
MITRE G0007Also known as BlueDelta, Sednit, Unit 26165, Forest Blizzard, Pawn Storm, GruesomeLarch, Fighting Ursa, Fancy Bear, FancyBear, UAC-0001, Sofacy
Reports
24
First seen
Nov 22, 2024
Last seen
Jul 24, 2026
Motivation
Espionage, Geopolitical
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
×1×3
Ukraine×3
Canada×1
United States×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×13T1190 Exploit Public-Facing Application ×13T1041 Exfiltration Over C2 Channel ×10T1059 Command and Scripting Interpreter ×6T1078 Valid Accounts ×6T1003 OS Credential Dumping ×6T1486 Data Encrypted for Impact ×6T1598 Phishing for Information ×5T1195 Supply Chain Compromise ×5T1110 Brute Force ×5T1021 Remote Services ×5T1071 Application Layer Protocol ×4
Indicators
cve ×58filename ×49domain ×40ip_v4 ×26url ×8email ×5registry_key ×4hash_sha256 ×3hash_sha1 ×2
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2026-21509 (exploited)CVE-2026-23760 (exploited)CVE-2026-22769 (exploited)CVE-2026-1340 (exploited)CVE-2025-55182 (exploited)CVE-2025-66376 (exploited)CVE-2026-1281 (exploited)CVE-2026-21513 (exploited)CVE-2021-27065 (exploited)CVE-2023-2868 (exploited)CVE-2021-26858 (exploited)CVE-2023-3519 (exploited)CVE-2023-7102 (exploited)CVE-2024-3400 (exploited)CVE-2020-12812 (exploited)CVE-2022-38028 (exploited)CVE-2025-26399 (exploited)CVE-2022-26923 (exploited)CVE-2021-26857 (exploited)CVE-2025-15556 (exploited)
Recent reports
High