APT28 is a Russia-linked nation-state actor known for long-term cyber espionage against government and military entities.
Analyst brief
APT28 (a.k.a. FANCY BEAR) is a nation-state threat actor linked to the Russian Federation, conducting long-term cyber espionage. It primarily targets government, military, security service, and administrative entities, with notable activity against the US, NATO, Ukraine, and Georgia. The group leverages spearphishing attachments for initial access, followed by PowerShell execution, credential access via Mimikatz (NTDS, Pass the Hash), and custom malware like ADVSTORESHELL and CHOPSTICK. Defenders should prioritize email security, monitor for anomalous PowerShell usage, and focus on detecting credential dumping and lateral movement attempts.
APT28
Pawn StormFANCY BEARSednit
nation-state
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and security organizations. It has been characterized as an advanced persistent threat.
origin (suspected)
🇷🇺Russia· state-sponsoredattribution confidence: medium (50)
target countries (as stated by the source)
GeorgiaFranceJordanUnited States
target sectors
GovernmentMilitaryGovernment, AdministrationSecurity Service