APT28
Aliases: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
Open interactive actor investigation
ATT&CK techniques
NTDST1589.001
CredentialsT1564.001
Hidden Files and DirectoriesT1583.003
Virtual Private ServerT1583.001
DomainsT1070.006
TimestompT1090.002
External ProxyT1566.001
Spearphishing AttachmentT1059.001
PowerShellT1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1547.001
Registry Run Keys / Startup FolderT1027.013
Encrypted/Encoded FileT1203
Exploitation for Client ExecutionT1586.002
Email AccountsT1114.002
Remote Email CollectionT1505.003
Web ShellT1584.008
Network DevicesT1550.002
Pass the HashT1037.001
Logon Script (Windows)T1588.002
ToolT1564.003
Hidden WindowT1090.003
Multi-hop ProxyT1567
Exfiltration Over Web ServiceT1056.001
KeyloggingT1083
File and Directory DiscoveryT1190
Exploit Public-Facing ApplicationT1039
Data from Network Shared DriveT1113
Screen CaptureT1110.001
Password GuessingT1070.001
Clear Windows Event LogsT1583.006
Web ServicesT1057
Process DiscoveryT1189
Drive-by CompromiseT1595.002
Vulnerability ScanningT1546.015
Component Object Model HijackingT1199
Trusted RelationshipT1120
Peripheral Device DiscoveryT1059.003
Windows Command ShellT1557.004
Evil TwinT1498
Network Denial of ServiceT1070.004
File DeletionT1560
Archive Collected DataT1105
Ingress Tool TransferT1598
Phishing for InformationT1559.002
Dynamic Data ExchangeT1036.005
Match Legitimate Name or LocationT1119
Automated CollectionT1078.004
Cloud AccountsT1221
Template InjectionT1005
Data from Local SystemT1213.002
SharepointT1078
Valid AccountsT1025
Data from Removable MediaT1071.001
Web ProtocolsT1213
Data from Information RepositoriesT1218.011
Rundll32T1560.001
Archive via UtilityT1140
Deobfuscate/Decode Files or InformationT1598.003
Spearphishing LinkT1542.003
BootkitT1071.003
Mail ProtocolsT1036
MasqueradingT1210
Exploitation of Remote ServicesT1014
RootkitT1204.002
Malicious FileT1550.001
Application Access TokenT1030
Data Transfer Size LimitsT1134.001
Token Impersonation/TheftT1074.002
Remote Data StagingT1092
Communication Through Removable MediaT1098.002
Additional Email Delegate PermissionsT1003
OS Credential DumpingT1040
Network SniffingT1068
Exploitation for Privilege EscalationT1137.002
Office TestT1528
Steal Application Access TokenT1110.003
Password SprayingT1204.001
Malicious LinkT1133
External Remote ServicesT1102.002
Bidirectional CommunicationT1001.001
Junk DataT1211
Exploitation for Defense EvasionT1003.001
LSASS MemoryT1573.001
Symmetric CryptographyT1074.001
Local Data StagingT1091
Replication Through Removable MediaT1110
Brute ForceT1021.002
SMB/Windows Admin SharesT1566.002
Spearphishing LinkT1059
Command and Scripting InterpreterT1082
System Information DiscoveryT1033
System Owner/User Discovery
Correlated CTI and IR reports
1200km CTI repository · explicit report mentionAttribution Methodology: How to Build, Defend, and Challenge a Threat Actor Attribution
1200km CTI repository · explicit report mentionCTI Research: Sandworm / APT44
1200km CTI repository · explicit report mentionCTI Research: Sandworm / APT44
1200km CTI repository · explicit report mentionCTI Kill Chain An Analyst Guide With Real World Evidence
1200km Medium · authored report mentionCTI Research Sandworm APT44
1200km Medium · authored report mentionComprehensive Guide to DoS and DDoS Attacks with MITRE ATT CK
1200km Medium · authored report mention