🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
FANCY BEAR (APT28)

/actor/fancy-bear-apt28/  ·  0 intel reports

Year Established
2004
Attribution
Russia (GRU Unit 26165 & 74455)
Motivation
Espionage, Influence Operations, Election Interference
Modus Operandi (MO)
Credential phishing, X-Agent/Sofacy malware, election infrastructure targeting, hack-and-leak operations
Primary Aliases
APT28, Pawn Storm, Sofacy, Sednit, STRONTIUM, Forest Blizzard, Iron Twilight, Tsar Team

Fancy Bear, designated APT28, is Russia's most publicly visible cyber espionage unit and arguably the most consequential threat actor in modern geopolitical history given their documented role in interfering with democratic elections across multiple nations. Active since at least 2004, APT28's operations span military espionage, political intelligence collection, disinformation campaigns, and hack-and-leak operations designed to influence public opinion and undermine democratic institutions globally.

APT28's most significant publicly documented operations include the 2016 compromise of the Democratic National Committee (DNC) and Hillary Clinton campaign chairman John Podesta's email account a hack-and-leak operation designed to embarrass and discredit international sporting governance.

The group has also targeted European election infrastructure, NATO and allied military networks, the Organisation for the Prohibition of Chemical Weapons (OPCW) and Ukrainian military artillery targeting systems, where deployed Android malware reportedly enabled Russian artillery units to geolocate Ukrainian howitzer positions during the 2014-2015 Donbas conflict.

APT28's technical toolkit includes the X-Agent (Sofacy) implant family, Zebrocy malware, and various credential-stealing tools delivered through spear-phishing campaigns and exploitation of public-facing services. In 2024, the US DOJ indicted six GRU officers associated with APT28 operations, and the UK, EU, and NATO allies issued coordinated condemnation.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles