G0007: APT28
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
Security context for executives and security teams
G0007: APT28 describes [APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(...
Executive priority
G0007: APT28 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0007: APT28 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0007: APT28 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
APT28
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1003.003 | NTDSSub-technique | |
| Enterprise | T1589.001 | CredentialsSub-technique | APT28 has harvested user's login credentials.CitationMicrosoft Targeting Elections September 2020 |
| Enterprise | T1591 | Gather Victim Org Information | APT28 has used large language models (LLMs) to gather information about satellite capabilities.CitationMSFT-AICitationOpenAI-CTI |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | |
| Enterprise | T1596 | Search Open Technical Databases | APT28 has used large language models (LLMs) to assist in script development and deployment.CitationMSFT-AICitationOpenAI-CTI |
| Enterprise | T1583.001 | DomainsSub-technique | |
| Enterprise | T1070.006 | TimestompSub-technique | |
| Enterprise | T1090.002 | External ProxySub-technique | APT28 used other victims as proxies to relay command traffic, for instance using a compromised Georgian military email server as a hop point to NATO victims. The group has also used a tool that acts as a proxy to allow C2 even if the victim is behind a router. APT28 has also used a machine to relay and obscure communications between CHOPSTICK and their server.[6]CitationBitdefender APT28 Dec 2015[3] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1059.001 | PowerShellSub-technique | |
| Enterprise | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolSub-technique | |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | |
| Enterprise | T1027.013 | Encrypted/Encoded FileSub-technique | |
| Enterprise | T1203 | Exploitation for Client Execution | |
| Enterprise | T1586.002 | Email AccountsSub-technique | APT28 has used compromised email accounts to send credential phishing emails.CitationGoogle TAG Ukraine Threat Landscape March 2022 |
| Enterprise | T1114.002 | Remote Email CollectionSub-technique | |
| Enterprise | T1505.003 | Web ShellSub-technique | |
| Enterprise | T1584.008 | Network DevicesSub-technique | |
| Enterprise | T1550.002 | Pass the HashSub-technique | APT28 has used pass the hash for lateral movement.CitationMicrosoft SIR Vol 19 |
| Enterprise | T1037.001 | Logon Script (Windows)Sub-technique | An APT28 loader Trojan adds the Registry key |
| Enterprise | T1588.002 | ToolSub-technique | |
| Enterprise | T1564.003 | Hidden WindowSub-technique | APT28 has used the WindowStyle parameter to conceal PowerShell windows.[11] CitationMcAfee APT28 DDE1 Nov 2017 |
| Enterprise | T1090.003 | Multi-hop ProxySub-technique | |
| Enterprise | T1567 | Exfiltration Over Web Service | |
| Enterprise | T1056.001 | KeyloggingSub-technique | |
| Enterprise | T1083 | File and Directory Discovery | |
| Enterprise | T1190 | Exploit Public-Facing Application | |
| Enterprise | T1669 | Wi-Fi Networks | |
| Enterprise | T1039 | Data from Network Shared Drive | |
| Enterprise | T1113 | Screen Capture | |
| Enterprise | T1110.001 | Password GuessingSub-technique | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days.[23] APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks.[2] |
| Enterprise | T1583.006 | Web ServicesSub-technique | APT28 has used newly-created Blogspot pages for credential harvesting operations.CitationGoogle TAG Ukraine Threat Landscape March 2022 |
| Enterprise | T1057 | Process Discovery | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.CitationUnit 42 Playbook Dec 2017 |
| Enterprise | T1189 | Drive-by Compromise | |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | APT28 has performed large-scale scans in an attempt to find vulnerable servers.CitationTrendMicro Pawn Storm 2019 |
| Enterprise | T1546.015 | Component Object Model HijackingSub-technique | |
| Enterprise | T1199 | Trusted Relationship | |
| Enterprise | T1120 | Peripheral Device Discovery | APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim.CitationMicrosoft SIR Vol 19 |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1557.004 | Evil TwinSub-technique | |
| Enterprise | T1498 | Network Denial of Service | |
| Enterprise | T1070.004 | File DeletionSub-technique | |
| Enterprise | T1560 | Archive Collected Data | |
| Enterprise | T1105 | Ingress Tool Transfer | |
| Enterprise | T1598 | Phishing for Information | |
| Enterprise | T1559.002 | Dynamic Data ExchangeSub-technique | |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | |
| Enterprise | T1119 | Automated Collection | |
| Enterprise | T1078.004 | Cloud AccountsSub-technique | |
| Enterprise | T1221 | Template Injection | APT28 used weaponized Microsoft Word documents abusing the remote template function to retrieve a malicious macro. CitationUnit42 Sofacy Dec 2018 |
| Enterprise | T1005 | Data from Local System | |
| Enterprise | T1213.002 | SharepointSub-technique | APT28 has collected information from Microsoft SharePoint services within target networks.CitationRSAC 2015 Abu Dhabi Stefano Maccaglia |
| Enterprise | T1078 | Valid Accounts | APT28 has used legitimate credentials to gain initial access, maintain access, and exfiltrate data from a victim network. The group has specifically used credentials stolen through a spearphishing email to login to the DCCC network. The group has also leveraged default manufacturer's passwords to gain initial access to corporate networks via IoT devices such as a VOIP phone, printer, and video decoder.CitationTrend Micro Pawn Storm April 2017[3][25][2] |
| Enterprise | T1025 | Data from Removable Media | An APT28 backdoor may collect the entire contents of an inserted USB device.CitationMicrosoft SIR Vol 19 |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | |
| Enterprise | T1213 | Data from Information Repositories | |
| Enterprise | T1218.011 | Rundll32Sub-technique | APT28 executed CHOPSTICK by using rundll32 commands such as |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | |
| Enterprise | T1598.003 | Spearphishing LinkSub-technique |
Groups, software, and campaigns
S0645: Wevtutil
S0160: certutil
S0023: CHOPSTICK
CHOPSTICK is a malware family of modular backdoors used by APT28. It has been used since at least 2012 and is usually dropped on victims as second-stage malware, though it has been used as first-stage malware in several cases. It has both Windows and Linux variants. [1] [2] [3] [4] It is tracked separately from the X-Agent for Android.
S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
S0193: Forfiles
Forfiles is a Windows utility commonly used in batch jobs to execute commands on one or more selected files or directories (ex: list all directories in a drive, read the first line of all files created yesterday, etc.). Forfiles can be executed from either the command line, Run window, or batch files/scripts. [1]
S0243: DealersChoice
DealersChoice is a Flash exploitation framework used by APT28. [1]
S0002: Mimikatz
S0045: ADVSTORESHELL
ADVSTORESHELL is a spying backdoor that has been used by APT28 from at least 2012 to 2016. It is generally used for long-term espionage and is deployed on targets deemed interesting after a reconnaissance phase. [1] [2]
S0351: Cannon
S0162: Komplex
S0135: HIDEDRV
S0044: JHUHUGIT
C0051: APT28 Nearest Neighbor Campaign
APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 5.3 | Current bundle | 82ecf9b2bb36… | ||
| 19.1 | 5.3 | Older bundle | 1d743dbb2ee5… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]NSA/FBI Drovorub August 2020
NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.
Open source URL - [2]Cybersecurity Advisory GRU Brute Force Campaign July 2021
NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
Open source URL - [3]DOJ GRU Indictment Jul 2018
Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
Open source URL - [4]Ars Technica GRU indictment Jul 2018
Gallagher, S. (2018, July 27). How they did it (and will likely try again): GRU hackers vs. US elections. Retrieved September 13, 2018.
Open source URL - [5]Crowdstrike DNC June 2016
Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
Open source URL - [6]FireEye APT28
FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
Open source URL - [7]SecureWorks TG-4127
SecureWorks Counter Threat Unit Threat Intelligence. (2016, June 16). Threat Group-4127 Targets Hillary Clinton Presidential Campaign. Retrieved August 3, 2016.
Open source URL - [8]FireEye APT28 January 2017
FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.
Open source URL - [9]GRIZZLY STEPPE JAR
Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017.
Open source URL - [10]Sofacy DealersChoice
Falcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.
Open source URL - [11]Palo Alto Sofacy 06-2018
Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.
Open source URL - [12]Symantec APT28 Oct 2018
Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.
Open source URL - [13]ESET Zebrocy May 2019
ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.
Open source URL - [14]US District Court Indictment GRU Oct 2018
Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.
Open source URL - [15]Nearest Neighbor Volexity
Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.
Open source URL - [16]Talos Seduploader Oct 2017
Mercer, W., et al. (2017, October 22). "Cyber Conflict" Decoy Document Used in Real Cyber Conflict. Retrieved November 2, 2018.
Open source URL - [17]Leonard TAG 2023
Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.
Open source URL - [18]Securelist Sofacy Feb 2018
Kaspersky Lab's Global Research & Analysis Team. (2018, February 20). A Slice of 2017 Sofacy Activity. Retrieved November 27, 2018.
Open source URL - [19]Accenture SNAKEMACKEREL Nov 2018
Accenture Security. (2018, November 29). SNAKEMACKEREL. Retrieved April 15, 2019.
Open source URL - [20]TrendMicro Pawn Storm Dec 2020
Hacquebord, F., Remorin, L. (2020, December 17). Pawn Storm’s Lack of Sophistication as a Strategy. Retrieved January 13, 2021.
Open source URL - [21]Secureworks IRON TWILIGHT Active Measures March 2017
Secureworks CTU. (2017, March 30). IRON TWILIGHT Supports Active Measures. Retrieved February 28, 2022.
Open source URL - [22]Kaspersky Sofacy
Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.
Open source URL - [23]Microsoft STRONTIUM New Patterns Cred Harvesting Sept 2020
Microsoft Threat Intelligence Center (MSTIC). (2020, September 10). STRONTIUM: Detecting new patterns in credential harvesting. Retrieved September 11, 2020.
Open source URL - [24]ESET Sednit Part 3
ESET. (2016, October). En Route with Sednit - Part 3: A Mysterious Downloader. Retrieved November 21, 2016.
- [25]Microsoft STRONTIUM Aug 2019
MSRC Team. (2019, August 5). Corporate IoT – a path to intrusion. Retrieved August 16, 2019.
Open source URL - [26]APT28
(Citation: FireEye APT28) (Citation: SecureWorks TG-4127) (Citation: Crowdstrike DNC June 2016) (Citation: Kaspersky Sofacy) (Citation: ESET Sednit Part 3) (Citation: Ars Technica GRU indictment Jul 2018)(Citation: Talos Seduploader Oct 2017)(Citation: Symantec APT28 Oct 2018)(Citation: Securelist Sofacy Feb 2018)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021)
- [27]FROZENLAKE
(Citation: Leonard TAG 2023)
- [28]Fancy Bear
(Citation: Crowdstrike DNC June 2016)(Citation: Kaspersky Sofacy)(Citation: ESET Sednit Part 3)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Talos Seduploader Oct 2017)(Citation: Symantec APT28 Oct 2018)(Citation: Securelist Sofacy Feb 2018)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021)
- [29]Forest Blizzard
(Citation: Microsoft Threat Actor Naming July 2023)
- [30]Group 74
(Citation: Talos Seduploader Oct 2017)
- [31]GruesomeLarch
(Citation: Nearest Neighbor Volexity)
- [32]IRON TWILIGHT
(Citation: Secureworks IRON TWILIGHT Profile)(Citation: Secureworks IRON TWILIGHT Active Measures March 2017)
- [33]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [34]Pawn Storm
(Citation: SecureWorks TG-4127)(Citation: ESET Sednit Part 3)(Citation: TrendMicro Pawn Storm Dec 2020)
- [35]SNAKEMACKEREL
(Citation: Accenture SNAKEMACKEREL Nov 2018)
- [36]STRONTIUM
(Citation: Kaspersky Sofacy)(Citation: ESET Sednit Part 3)(Citation: Microsoft STRONTIUM Aug 2019)(Citation: Microsoft STRONTIUM New Patterns Cred Harvesting Sept 2020)(Citation: TrendMicro Pawn Storm Dec 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021)
- [37]Secureworks IRON TWILIGHT Profile
Secureworks CTU. (n.d.). IRON TWILIGHT. Retrieved February 28, 2022.
Open source URL - [38]Sednit
This designation has been used in reporting both to refer to the threat group and its associated malware [JHUHUGIT](https://attack.mitre.org/software/S0044).(Citation: FireEye APT28 January 2017)(Citation: SecureWorks TG-4127)(Citation: Kaspersky Sofacy)(Citation: Ars Technica GRU indictment Jul 2018)
- [39]Sofacy
This designation has been used in reporting both to refer to the threat group and its associated malware.(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: Crowdstrike DNC June 2016)(Citation: ESET Sednit Part 3)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Talos Seduploader Oct 2017)
- [40]Swallowtail
(Citation: Symantec APT28 Oct 2018)
- [41]TG-4127
(Citation: SecureWorks TG-4127)
- [42]Threat Group-4127
(Citation: SecureWorks TG-4127)
- [43]Tsar Team
(Citation: ESET Sednit Part 3)(Citation: Talos Seduploader Oct 2017)(Citation: Talos Seduploader Oct 2017)
- [44]mitre-attackG0007Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
