APT28
Also tracked as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
- Documented techniques
- 93
- Assessed origin
- Russia
- First seen
- 2004
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance6
resource development7
initial access5
execution6
persistence6
privilege escalation2
credential access9
discovery3
lateral movement5
collection13
- T1005 Data from Local System
- T1025 Data from Removable Media
- T1039 Data from Network Shared Drive
- T1056.001 Keylogging
- T1074.001 Local Data Staging
- T1074.002 Remote Data Staging
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1119 Automated Collection
- T1213 Data from Information Repositories
- T1213.002 Sharepoint
- T1560 Archive Collected Data
- T1560.001 Archive via Utility
command and control9
exfiltration3
defense impairment1
stealth17
- T1014 Rootkit
- T1027.013 Encrypted/Encoded File
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1078 Valid Accounts
- T1078.004 Cloud Accounts
- T1134.001 Token Impersonation/Theft
- T1140 Deobfuscate/Decode Files or Information
- T1211 Exploitation for Stealth
- T1218.011 Rundll32
- T1221 Template Injection
- T1542.003 Bootkit
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1684.001 Impersonation
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.