{"id":433,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2004<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Russia (GRU Unit 26165 &amp; 74455)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Influence Operations, Election Interference<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Credential phishing, X-Agent\/Sofacy malware, election infrastructure targeting, hack-and-leak operations<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">APT28, Pawn Storm, Sofacy, Sednit, STRONTIUM, Forest Blizzard, Iron Twilight, Tsar Team<\/div>\n  <\/div>\n<\/div>\n<p>Fancy Bear, designated APT28, is Russia's most publicly visible cyber espionage unit \u2014 attributed to the GRU's 85th Main Special Service Centre (Unit 26165) and the GRU's 74455 unit (Sandworm adjacent) \u2014 and arguably the most consequential threat actor in modern geopolitical history given their documented role in interfering with democratic elections across multiple nations. Active since at least 2004, APT28's operations span military espionage, political intelligence collection, disinformation campaigns, and hack-and-leak operations designed to influence public opinion and undermine democratic institutions globally.<\/p>\n<p>APT28's most significant publicly documented operations include the 2016 compromise of the Democratic National Committee (DNC) and Hillary Clinton campaign chairman John Podesta's email account \u2014 with stolen emails subsequently published through WikiLeaks and Guccifer 2.0 personas in what US intelligence agencies assessed as a deliberate Russian influence operation targeting the US presidential election. The same year, APT28 compromised the World Anti-Doping Agency (WADA) and published medical records of Olympic athletes in retaliation for Russia's doping ban \u2014 a hack-and-leak operation designed to embarrass and discredit international sporting governance.<\/p>\n<p>The group has also targeted European election infrastructure, NATO and allied military networks, the Organisation for the Prohibition of Chemical Weapons (OPCW) \u2014 which was investigating the Novichok poisoning of Sergei Skripal \u2014 and Ukrainian military artillery targeting systems, where deployed Android malware reportedly enabled Russian artillery units to geolocate Ukrainian howitzer positions during the 2014-2015 Donbas conflict.<\/p>\n<p>APT28's technical toolkit includes the X-Agent (Sofacy) implant family, Zebrocy malware, and various credential-stealing tools delivered through spear-phishing campaigns and exploitation of public-facing services. In 2024, the US DOJ indicted six GRU officers associated with APT28 operations, and the UK, EU, and NATO allies issued coordinated condemnation \u2014 reflecting the group's sustained priority as a top-tier threat to Western democratic institutions and national security.<\/p>","link":"https:\/\/cyberasia.io\/actor\/fancy-bear-apt28\/","name":"Fancy Bear (APT28)","slug":"fancy-bear-apt28","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}