APT28
Also tracked as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
- Known attack methods
- 93
- Origin
- Russia
- First seen
- 2004
- Last seen
- 2024-11
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 5 used
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 5 used
Execution
20 techniques · 4 used
Persistence
22 techniques · 6 used
Privilege Escalation
13 techniques · 2 used
Stealth
30 techniques · 13 used
Defense Impairment
18 techniques · 1 used
Credential Access
17 techniques · 5 used
Discovery
34 techniques · 3 used
Lateral Movement
9 techniques · 4 used
Collection
17 techniques · 10 used
Command and Control
18 techniques · 7 used
Exfiltration
9 techniques · 3 used
Impact
15 techniques · 1 used
Reconnaissance6
Resource development7
Initial access5
Execution6
Persistence6
Privilege escalation2
Stealth17
- T1014Rootkit
- T1027.013Encrypted/Encoded File
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1070.004File Deletion
- T1070.006Timestomp
- T1078Valid Accounts
- T1078.004Cloud Accounts
- T1134.001Token Impersonation/Theft
- T1140Deobfuscate/Decode Files or Information
- T1211Exploitation for Stealth
- T1218.011Rundll32
- T1221Template Injection
- T1542.003Bootkit
- T1564.001Hidden Files and Directories
- T1564.003Hidden Window
- T1684.001Impersonation
Defense impairment1
Credential access9
Lateral movement5
Collection13
- T1005Data from Local System
- T1025Data from Removable Media
- T1039Data from Network Shared Drive
- T1056.001Keylogging
- T1074.001Local Data Staging
- T1074.002Remote Data Staging
- T1113Screen Capture
- T1114.002Remote Email Collection
- T1119Automated Collection
- T1213Data from Information Repositories
- T1213.002Sharepoint
- T1560Archive Collected Data
- T1560.001Archive via Utility
Command and control9
Exfiltration3
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.