RussiaFormally attributedActiveMITRE G0007

APT28

Coverage omission — Eastern

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
23.6
High signal strength
Mentions32
Sources7
High conf.25
Last seenMay 2026
First observed
2017-05-31
Last active
Active
Origin
Russia — attributed by US, UK, EU governments to GRU (Russian military intelligence)
Aliases
25
Techniques
93
Campaigns
11
Russia — attributed by US, UK, EU governments to GRU (Russian military intelligence)consensus confidence
TargetsGovernmentMilitaryPolitical OrganisationsNGOMedia
RegionsEuUsUaNatoGeFr

Attribution signals

32 mentions · 7 sources
#1attributed tohigh
Unspecified
krebs
May 2026

"Forest Blizzard is attributed to the military intelligence units within Russia's General Staff Main Intelligence Directorate (GRU)"

#2attributed tohigh
Unspecified
krebs
May 2026

"Also known as APT28 and Fancy Bear, Forest Blizzard is attributed to the military intelligence units within Russia's General Staff Main Intelligence Directorate (GRU)"

#3assess with high confidencehigh
Code similarity
eset
May 2026

"We therefore assess with high confidence that both the 2018 samples and the 2024 SlimAgent sample were built from the same codebase."

#4attribute with high confidencehigh
Code similarityMalware
eset
May 2026

"Based on these similarities, we believe that SlimAgent is an evolution of the Xagent keylogger module, which has been deployed as a standalone component since at least 2018. Moreover, because Xagent is a custom toolset used exclusively by the Sednit group for more than six years, we attribute SlimAgent to Sednit with high confidence."

#5analyzedhigh
TTP match
checkpoint
May 2026

"Researchers have analyzed the activity of Russian threat group APT28 (aka Fancy Bear). The group has recently targeted Ukraine as well as its European defense supply chain partners with a toolset dubbed PRIXMES"

Campaign: PRIXMES
#6derived fromhigh
MalwareCode similarity
eset
May 2026

"SlimAgent code was derived from Xagent, Sednit's flagship backdoor from the 2010s."

#7exploitedhigh
Victimology
proofpoint
May 2026

"The flaw was exploited as a zero-day alongside CVE-2026-21513 by TA422 in attacks targeting Ukraine and EU member states beginning in late 2025."

#8exploitationhigh
Malware
recorded-future
May 2026

"Active exploitation by APT28"

Campaign: Operation Neusploit
#9leveragedhigh
InfrastructureTTP match
recorded-future
May 2026

"APT28 exploits MSHTML flaw: The Russian state-sponsored group leveraged CVE-2026-21513 via malicious Windows Shortcut files for multi-stage payload delivery"

#10exploitedhigh
MalwareTTP match
recorded-future
May 2026

"Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants"

Campaign: Operation Neusploit
#11exploitationhigh
MalwareTTP match
recorded-future
May 2026

"Zero-day exploitation by Russian state-sponsored actors bypasses Office security features, enabling delivery of email collection implants and backdoors."

Campaign: Operation Neusploit
#12exploitedhigh
MalwareTTP match
recorded-future
May 2026

"APT28's Operation Neusploit marked January's most sophisticated campaign: Exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files"

Campaign: Operation Neusploit

Hedge terms observed

accused ofalmost certainlyalso found inanalyzedassess with high confidenceattribute with high confidenceattributed tocalled outconsistent withderived fromexploitationexploitedhas been weaponized byhas exploitedhas previously been linkedhave been exploitingleveragedlinked tonamedobservedpresumed to bereemergedseentargeted byunspecified