LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0007: APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.CitationNSA/FBI Drovorub August 2020CitationCybersecurity Advisory GRU Brute Force Campaign July 2021 This group has been active since at least 2004.CitationDOJ GRU Indictment Jul 2018CitationArs Technica GRU indictment Jul 2018CitationCrowdstrike DNC June 2016CitationFireEye APT28CitationSecureWorks TG-4127CitationFireEye APT28 January 2017CitationGRIZZLY STEPPE JARCitationSofacy DealersChoiceCitationPalo Alto Sofacy 06-2018CitationSymantec APT28 Oct 2018CitationESET Zebrocy May 2019

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.CitationCrowdstrike DNC June 2016 In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.CitationUS District Court Indictment GRU Oct 2018 Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

EnterpriseG0007GroupObject v5.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

APT28 matters because ATT&CK describes a long-running, state-attributed intrusion set with documented operations against political, international, scientific, and other sensitive organizations. For leaders, the practical issue is not the name itself; it is whether the organization can withstand credential theft, living-off-the-land activity, malware across multiple endpoint types, cloud/enterprise account attacks, and even close-access or nearby Wi-Fi enabled intrusion paths when the target is strategically interesting.

Executive priority

Treat APT28 as a planning scenario for high-consequence intrusion readiness: executive teams should ask whether identity controls, cloud authentication evidence, endpoint visibility, remote access monitoring, and incident response playbooks can support fast decisions during a suspected espionage or targeted intrusion. The relationship set includes credential tools, backdoors, proxy tooling, Windows utilities, macOS malware, Linux-capable malware, and an Android malware reference, so budget and assurance discussions should focus on coverage across identity, endpoint, network, and cloud—not only perimeter prevention.

Technical view

ATT&CK does not provide a group-level detection section or group-level platforms/tactics for this object, so SOC and IR validation should be driven by the related software and campaign context. Confirm monitoring for credential dumping and harvesting behaviors associated with Mimikatz and OLDBAIT; administrative and living-off-the-land utility use such as Net, certutil, Forfiles, Winexe, and Koadic; backdoor/downloader families including CHOPSTICK, ADVSTORESHELL, Downdelph, CORESHELL, Zebrocy, Cannon, XAgentOSX, and Komplex; proxy/anonymity tooling such as XTunnel and Tor; and removable-media or air-gapped collection risk associated with USBStealer. The C0051 relationship adds a useful readiness check for nearby Wi-Fi exposure, living-off-the-land tradecraft, and vulnerability response around CVE-2022-38028 in the historical campaign context supplied by ATT&CK.

Likely telemetry

  • Identity and authentication logs, including failed/successful login patterns and cloud authentication records where available
  • Endpoint process creation and command-line telemetry for Windows administrative utilities and scripting/post-exploitation frameworks
  • Credential access signals from Windows hosts, including suspicious access to credential material and known credential dumping tool detections
  • Network connection, proxy, DNS, and egress telemetry for unusual tunneling, Tor use, or C2-like communications
  • EDR/AV detections and file telemetry for related malware families and downloaders

Detection direction

  • Map existing detections to the related ATT&CK software rather than relying on the APT28 name alone; the object has no official group-level detection guidance.
  • Prioritize behavior-based analytics for credential access, suspicious administrative utility use, remote command execution, downloader/backdoor execution, and proxy/tunneling behavior.
  • Tune living-off-the-land detections carefully: Net, certutil, Forfiles, Winexe, and similar tools may be legitimate, so detections should account for user, host role, parent process, command line, destination, timing, and change-control context.
  • Validate identity and cloud log retention because the supplied references include a GRU brute-force campaign against enterprise and cloud environments; absence of these logs is a material blind spot.
  • Assess wireless and physical-proximity logging for high-risk sites, since the related APT28 Nearest Neighbor Campaign describes use of nearby Wi-Fi networks to gain initial access.

Mitigation priorities

  • Start with identity hardening: strong MFA, reduced password reuse, monitoring of brute-force patterns, and rapid credential reset procedures for suspected compromise.
  • Harden and monitor administrative tooling rather than attempting to block every native utility; restrict unnecessary remote administration paths and require privileged activity logging.
  • Maintain endpoint detection and response coverage across operating systems actually used by the organization, including Windows and any macOS/Linux populations reflected in the related software set.
  • Segment sensitive environments and monitor removable-media use, especially where air-gapped, regulated, research, or operational systems exist.
  • Include wireless security and physical proximity assumptions in risk reviews for sensitive sites, especially where nearby network access could create an initial-access path.
Additional notes and limits

The ATT&CK object is a group profile, not a detection rule. Its value is in the relationship set: APT28 is connected to many tools and malware families, plus a campaign involving living-off-the-land techniques, CVE-2022-38028, and nearby Wi-Fi access. This supports a broad readiness assessment across identity, endpoint, cloud authentication evidence, network egress, vulnerability management, and site-level wireless controls.

No official group-level detection text, tactics, or platforms are provided for APT28 in the supplied fields. Platform observations come from related software objects, not from the group object itself. Local exposure, logging availability, control effectiveness, and relevance to a specific organization require environment-specific validation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.CitationNSA/FBI Drovorub August 2020CitationCybersecurity Advisory GRU Brute Force Campaign July 2021 This group has been active since at least 2004.CitationDOJ GRU Indictment Jul 2018CitationArs Technica GRU indictment Jul 2018CitationCrowdstrike DNC June 2016CitationFireEye APT28CitationSecureWorks TG-4127CitationFireEye APT28 January 2017CitationGRIZZLY STEPPE JARCitationSofacy DealersChoiceCitationPalo Alto Sofacy 06-2018CitationSymantec APT28 Oct 2018CitationESET Zebrocy May 2019

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.CitationCrowdstrike DNC June 2016 In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.CitationUS District Court Indictment GRU Oct 2018 Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
5.3
Created
Modified
Raw hash
1d743dbb2ee5a707...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.