s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

AI-SEARCH-apt28 medium

📛 Threat Title

AI threat search: APT28

Category: ai-threat-search First seen: Last updated:

Description

AI-discovered findings for topic: 'APT28'. Run at 2026-08-05T01:26:03.553485Z. DuckDuckGo returned 10 result(s); the AI Forensic Validator classified 0 IOC(s) as valid. CVEs mentioned: CVE-2026-21509

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (32)

  • PDF APT28 exploits known vulnerability to carry out reconnaissance and ...

    We assess that APT28 is almost certainly the Russian General Staff Main Intelligence Directorate (GRU) 85th special Service Centre (GTsSS) Military Intelligence Unit 26165. APT28 (also known as Fancy Bear, STRONTIUM, Pawn Storm, the Sednit Gang and Sofacy) is a highly skilled threat actor.

  • APT28 - Cyber Kill Chain

    APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.

  • Fancy Bear (APT28) Threat Actor Profile: TTPs, IOCs & Attacks | Huntress

    Fancy Bear, also known as APT28 , is a Russian state-sponsored cyber espionage group active since at least 2004. This group represents a highly-skilled Advanced Persistent Threat (APT) actor, consistently linked to the Main Intelligence Directorate of the Russian Federation (GRU). Fancy Bear is known for its use of zero-day vulnerabilities, spear-phishing campaigns, and sophisticated malware in ...

  • Sofacy AKA APT28: Threat Actor Profile - Cyble

    Threat Actor Profile: APT28 (Fancy Bear) Cyble showcases its findings on APT28 , AKA Fancy Bear, a notorious APT group, and the tactics, targets, tools, and techniques it uses in its cyber espionage activities.

  • APT Groups Tracker 2026: Active Nation-State Threat Actors

    Mandiant / Google Threat Intelligence : Uses the APT numbering system ( APT28 , APT29, APT41, etc.) and UNC designations for uncategorized groups. Mandiant's annual M-Trends report is essential reading for understanding year-over-year trends in nation-state activity.

  • APT28 (Fancy Bear / Sofacy / Sednit / Forest Blizzard) - Threat Actor ...

    1. Executive Summary APT28 is a long-running Russian state-aligned cyber espionage actor widely attributed to the GRU's 85th Main Special Service Center (GTsSS), military unit 26165, active since at least 2004. (attack.mitre.org) The group is assessed by multiple governments to conduct both intelligence collection and "hack-and-leak" influence activity, with sustained targeting of ...

  • APT28, an evolution of tradecraft - sekoia.com

    Context Sekoia's Threat Detection & Research (TDR) team has been tracking APT28 for several years. The intrusion set, also known as Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm or Sednit and publicly attributed to the GRU's Unit 26165, is one of the most prolific and persistent state-sponsored actors we monitor. Its operations span in two decades and consistently target government ...

  • APT28 | Threat Actor Profiles

    Overview APT28 (also tracked as Fancy Bear, Forest Blizzard, STRONTIUM, Pawn Storm, Sednit, and Sofacy) is a Russian military intelligence (GRU) cyber espionage group attributed to Unit 26165 of the 85th Main Special Service Center (GTsSS). Active since at least 2004, APT28 conducts intelligence collection aligned with Russian military and geopolitical objectives. The group is known for ...

  • APT28: Russia's Persistent Cyber Espionage Arm - Brandefense

    Introduction APT28 , also known as Fancy Bear, Sofacy, Sednit, STRONTIUM, and various other epithets, is the most recognizable and longstanding advanced persistent threat (APT) group still in existence. APT28 is the tip of the spear of Russian state-affiliated cyber capabilities. APT28 has been traced back as far as 2004, and the group has been assessed with high confidence by national ...

  • PDF APT28: A Window into Russia s Cyber Espionage Operations? | FireEye

    The activity that we profile in this paper appears to be the work of a skilled team of developers and operators collecting intelligence on defense and geopolitical issues - intelligence that would only be useful to a government. We believe that this is an advanced persistent threat (APT) group engaged in espionage against political and military targets including the country of Georgia ...

  • APT28: Inside Russia's Fancy Bear Military Intelligence Hacking Unit

    When cybersecurity professionals discuss the most aggressive and destructive nation-state threat actors, APT28 inevitably dominates the conversation. Known by numerous aliases including Fancy Bear, Sofacy, Sednit, and Pawn Storm, this Russian military intelligence hacking unit has conducted some of the most brazen and consequential cyberattacks in history. From disrupting democratic elections ...

  • Top 10 Advanced Persistent Threat (APT) Groups in 2026

    What Are Advanced Persistent Threat (APT) Groups? Advanced Persistent Threat (APT) groups represent highly strategic cyber actors focused on long-term infiltration rather than quick attacks. Such groups slip into networks quietly and remain active for extended periods to gather intelligence or prepare disruption.

  • APT28 Archives - SecurityWeek

    US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking The APT28 threat group exploited vulnerable TP-Link and MikroTik routers to conduct adversary-in-the-middle (AitM) attacks.

  • APT28 Malware | Russia's Cyber Espionage Operations Report | Google ...

    This report focuses on a threat group that we have designated as APT28 . While APT28's malware is fairly well known in the cybersecurity community, our report details additional information exposing ongoing, focused operations that we believe indicate a government sponsor based in Moscow.

  • APT28 Uses Microsoft Office CVE-2026-21509 in Espionage-Focused Malware ...

    APT28 exploited a Microsoft Office flaw to deliver MiniDoor and Covenant Grunt malware in targeted attacks across Ukraine and Eastern Europe.

  • APT28 Weaponizes Outlook Zero-Click Flaw to Steal Net-NTLMv2 Hashes ...

    Russian state-sponsored threat actor APT28 , also known as Fancy Bear or Forest Blizzard, has aggressively shifted its cyber espionage tactics to focus on zero-click vulnerabilities and edge infrastructure. Recent threat intelligence reveals that the group, publicly attributed to the GRU's Unit 26165, has weaponized a critical Outlook flaw to silently extract Net-NTLMv2 hashes from NATO ...

  • APT28's Stealthy Multi-Stage Campaign Leveraging CVE‑2026‑21509 and ...

    Attribution to APT28 This campaign is attributed to APT28 with high confidence based on technical indicators and victimology. CERT-UA officially attributed the January 2026 attacks to threat actor UAC-0001 [1], which corresponds to APT28 (Fancy Bear), a unit of Russia's GRU military intelligence .

  • threat-intelligence-reports/reports/2026-06-apt28-military ... - GitHub

    I assess APT28 as a relevant public-source case study for espionage and military or political intelligence collection. This report focuses on observable behavior, confidence, victimology, and defensive implications rather than unsourced attribution claims. I prioritize ATT&CK-mapped behavior and source-based observables over stale atomic ...

  • CVE-2026-32202 IOCs, Detection Rules & APT28 TTPs: Complete…

    CVE-2026-32202: APT28 Zero-Click NTLM Credential Theft, IOCs and Detection Reference Sources: Microsoft Security Response Center, CVE-2026-32202 Advisory | Microsoft Threat Intelligence , APT28 Active Exploitation | CISA Known Exploited Vulnerabilities Catalog | SigmaHQ Detection Rules Repository

  • PDF APT28 exploit routers to enable DNS hijacking operations

    For more information on APT28 activity, see the advisories 'Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure', 'APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on cisco routers' and 'UK and allies expose Russian intelligence campaign targeting western logistics and ...

  • A Shortcut to Coercion: Incomplete Patch of APT28's Zero-Day Leads to ...

    Akamai researchers reveal how an incomplete patch for APT28's zero-day led to CVE-2026-32202, a zero-click vulnerability enabling NTLM authentication coercion.

  • PDF Alert: I-260407-PSA | 07 APRIL 2026 Russian GRU Exploiting Vulnerable ...

    GRU Exploiting Vulnerable Routers to Steal Sensitive Information Russian General Staff Main Intelligence Directorate (GRU) cyber actors are exploiting vulnerable routers worldwide to intercept and steal sensitive military, government, and critical infrastructure information. The U.S. Department of Justice and the FBI recently disrupted a GRU network of compromised small-office home-office ...

  • Russian State-Linked APT28 Exploits SOHO Routers in Global DNS ...

    The Microsoft Threat Intelligence team, in its analysis of the campaign, attributed the activity to APT28 and its sub-group tracked as Storm-2754. The tech giant said it identified more than 200 organizations and 5,000 consumer devices impacted by the threat actor's malicious DNS infrastructure.

  • APT28 exploit routers to enable DNS hijacking operations

    For more information on APT28 activity, see the advisories ' Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure ', ' APT28 exploits known vulnerability to carry out reconnaissance and deploy malware on cisco routers ' and ' UK and allies expose Russian intelligence campaign targeting western logistics and ...

  • APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit ...

    APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.

  • APT28 Cyber Threat Profile and Detailed TTPs

    Explore APT28's history, major campaigns, and MITRE ATT&CK TTPs. Learn how to simulate and defend against this threat with Picus.

  • PDF APT28 exploits known vulnerability to carry out reconnaissance and ...

    APT28 exploits known vulnerability to carry out reconnaissance of routers and deploy malware APT28 accesses poorly maintained Cisco routers and deploys malware on unpatched devices using CVE-2017-6742.

  • PDF APT28 ADVANCED PERS - eurepoc.eu

    State-integrated hacking group: Based on the reports about the group's alleged political affiliations and several indictments against GRU agents, which claim to identify APT28 members, the group is considered a de facto agent of the Russian state, more specifically its military intelligence branch (GRU). Furthermore, its extensive operations against defence ministries, NATO installations ...

  • APT28 (Fancy Bear / Sofacy / Sednit / Forest Blizzard) - Threat Actor ...

    1. Executive Summary APT28 is a long-running Russian state-aligned cyber espionage actor widely attributed to the GRU's 85th Main Special Service Center (GTsSS), military unit 26165, active since at least 2004. (attack.mitre.org) The group is assessed by multiple governments to conduct both intelligence collection and "hack-and-leak" influence activity, with sustained targeting of ...

  • APT28 Intelligence Dashboard Immediately Available for ThreatConnect

    Centralized Intelligence : Compiles APT28 -specific indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs) from open-source intelligence , threat feeds, and internal telemetry. Real-Time Threat Tracking: Offers continuous updates on APT28's attack infrastructure, victimology trends, and newly observed techniques.

  • APT28 Exploits Known Vulnerability to Carry Out Reconnaissance and ...

    We assess that APT28 is almost certainly the Russian General Staff Main Intelligence Directorate (GRU) 85th special Service Centre (GTsSS) Military Intelligence Unit 26165 . APT28 (also known as Fancy Bear, STRONTIUM, Pawn Storm, the Sednit Gang and Sofacy) is a highly skilled threat actor. Download the UK PDF version of this report:

  • APT28 / Fancy Bear: Russian State Sponsored APT - Threat Actors

    Overview APT28 , also known as Fancy Bear, is a sophisticated and prolific advanced persistent threat (APT) group strongly linked to the Russian Main Intelligence Directorate (GRU).

Remediations (10)

  • web:cybersecuritynews.com

    APT28 fuses LLM into live malware via Hugging Face API, delivering dynamic shell commands through phishing PDF ZIP decoys.

  • web:guardsix.com

    Threat actors may exploit public LLM APIs to generate malicious code, obfuscate payloads, or automate reconnaissance—much like APT28 did with LameHug. Additionally, risks such as prompt injection, data leakage, or the use of unvetted open-source models in internal systems can introduce new attack vectors.

  • web:securityonline.info

    Google exposed AI -enabled malware like PROMPTFLUX, which uses the Gemini API to dynamically rewrite its own source code to evade detection. APT28 was seen deploying an LLM-assisted stealer.

  • web:sourcedev.tr

    In April 2026, a joint advisory from the NSA, FBI, and partners across 15+ NATO-aligned nations confirmed that APT28 — the GRU-linked threat actor also tracked as Fancy Bear and Forest Blizzard — had compromised thousands of SOHO routers worldwide. By exploiting a known authentication flaw in TP-Link and MikroTik devices, the group modified DNS and DHCP settings to redirect traffic through ...

  • web:treadstone71.substack.com

    The sharing and collation of these indicators will be instrumental in the early detection of AI -crafted attacks. In conclusion, AI is poised to become both a formidable weapon and an essential shield in cyberspace. APT28's venture into LLM-assisted hacking is likely the vanguard of a broader trend, with other threat actors rapidly following suit.

  • web:triagesecurity.ai

    Recent intelligence details sustained campaigns by the APT28 threat actor targeting government, defense, and critical infrastructure networks. By understanding their use of specific vulnerabilities and router-based DNS redirection, security teams can implement targeted, foundational defenses to protect sensitive data.

  • web:www.esecurityplanet.com

    APT28's new "LameHug" malware uses LLMs to generate basic commands, a strikingly clumsy move from an otherwise advanced threat group.

  • web:www.ic3.gov

    Understanding the DNS Hijacking Operations Since at least 2024, Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28 , Fancy Bear, and Forest Blizzard — have been collecting credentials and exploiting vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224. The GRU actors changed the devices' dynamic host ...

  • web:www.picussecurity.com

    Explore APT28's history, major campaigns, and MITRE ATT&CK TTPs. Learn how to simulate and defend against this threat with Picus.

  • web:www.threatintelreport.com

    APT28 (Fancy Bear / Sofacy / Sednit / Forest Blizzard) - Threat Actor Profile By Threat Analyst 20 February 2026 Cybercrime_Organizations, Incident_Response, Malware_Detection, Nation_State_Actors, Threat_Hunting

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.