APT28
Russian state-sponsored (GRU) · Espionage / election interference / influence operations
Tactics, Techniques & Procedures (TTPs)
- Spear-phishing with credential-harvesting lures
- Lookalike domain registration targeting government SSO and OWA
- MASEPIE Python backdoor using IMAP for C2
- OCEANMAP .NET backdoor
- Zebrocy loader and X-Agent implant
- RouterStealer network device compromise
Known Targets
Analyst Notes
GRU Unit 26165 and 85th GTsSS. Responsible for the DNC hack (2016), French election interference targeting En Marche (2017), and the Bundestag intrusion (2015). Among the most active and destructive nation-state actors globally, with a documented pattern of pre-election intelligence collection followed by timed leaks.
Also Known As
Intelligence Reports
APT28: Russia's GRU Hacking Unit and the Twenty-Year Campaign Against Western Democracy
APT28 — Fancy Bear, Forest Blizzard, GRU Unit 26165 — is Russia's Military Intelligence cyber arm and the most prolific nation-state attacker targeting Western governments, militaries, and democratic institutions. This deep dive covers their operational history, tradecraft, tooling, and current targeting priorities.
APT28 Intensifies Targeting of European Government Networks Ahead of 2026 Election Cycle
Russia's GRU-linked APT28 has escalated spear-phishing and credential-harvesting operations against European government ministries, NATO-adjacent bodies, and political parties in the run-up to elections across the continent.