{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt28",
    "slug": "apt28",
    "name": "APT28",
    "shortName": "APT28",
    "country": "Russia",
    "countryCode": "RU",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2004",
    "prominence": 98,
    "mitreGroupId": "G0007",
    "malpediaSlug": "apt28",
    "tagline": "GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.",
    "bio": "APT28 is the cyber operations arm of Russia's Main Intelligence Directorate (GRU), specifically Unit 26165 — the 85th Main Special Service Centre. It is the most thoroughly documented state hacking group in the public record, largely because the U.S. Department of Justice has twice indicted its officers by name and photograph.\n\nThe group's tradecraft is best understood as intelligence collection that accepts political risk. Where the SVR's APT29 optimises for staying unseen for years, APT28 runs high-volume credential phishing and burns infrastructure quickly. It has repeatedly crossed from collection into influence operations — stealing documents and releasing them through fronts such as DCLeaks, Guccifer 2.0, and Fancy Bears' Hack Team.\n\nIts target set tracks Russian military and political priorities with unusual fidelity: NATO member defence ministries, European parliaments, the anti-doping bodies that banned Russian athletes, the OPCW while it investigated the Skripal poisoning, and — since February 2022 — the logistics companies, rail operators, and border-crossing systems moving aid into Ukraine.\n\nAPT28 is also a persistent innovator at the low level. In 2018 ESET documented LoJax, the first UEFI rootkit ever found in the wild, which survives both operating-system reinstallation and hard drive replacement.",
    "attribution": {
      "sponsor": "Russia",
      "service": "GRU — Main Intelligence Directorate of the General Staff",
      "unit": "Unit 26165",
      "unitDetail": "85th Main Special Service Centre (GTsSS), Komsomolsky Prospekt 20, Moscow",
      "confidence": "confirmed",
      "summary": "Attributed to GRU Unit 26165 by name-level U.S. federal indictment. The July 2018 Special Counsel indictment charged twelve GRU officers across Units 26165 and 74455 for the 2016 election interference operation, describing the office locations, roles, and search histories of individual officers. A second indictment in October 2018 charged seven Unit 26165 officers over the WADA, USADA, and OPCW intrusions, including close-access operations run from a parked car in The Hague. The UK NCSC, EU, and multiple NATO governments have issued concurring attributions.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Indictment: United States v. Netyksho et al. — 12 GRU officers charged in 2016 election interference",
          "url": "https://www.justice.gov/file/1080281/download",
          "date": "2018-07-13"
        },
        {
          "org": "U.S. Department of Justice",
          "title": "Indictment: US v. Aleksei Morenets et al. — 7 GRU officers charged over WADA/OPCW hacking",
          "url": "https://www.justice.gov/opa/page/file/1098481/download",
          "date": "2018-10-04"
        },
        {
          "org": "CISA / NSA / FBI / NCSC-UK",
          "title": "Russian GRU Conducting Global Brute Force Campaign (Unit 26165)",
          "url": "https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF",
          "date": "2021-07-01"
        },
        {
          "org": "NSA / CISA / FBI and international partners",
          "title": "Russian GRU Unit 26165 targeting Western logistics entities and technology companies",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a",
          "date": "2025-05-21"
        }
      ]
    },
    "motivations": [
      "espionage",
      "information-operations",
      "sabotage"
    ],
    "targetSectors": [
      "Government",
      "Defense",
      "Aerospace",
      "Media & Journalism",
      "Think Tanks & Academia",
      "Political Organizations",
      "Diplomatic",
      "Transportation",
      "Energy",
      "Technology"
    ],
    "targetCountries": [
      "United States",
      "Ukraine",
      "Germany",
      "France",
      "Poland",
      "United Kingdom",
      "Norway",
      "Netherlands",
      "Czechia",
      "Georgia",
      "Türkiye"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "APT28",
        "url": "https://attack.mitre.org/groups/G0007/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Forest Blizzard",
        "correlation": "exact",
        "note": "Formerly STRONTIUM, renamed April 2023"
      },
      {
        "org": "microsoft",
        "name": "STRONTIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Fancy Bear",
        "url": "https://www.crowdstrike.com/adversaries/fancy-bear/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT28",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "IRON TWILIGHT",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "TG-4127",
        "correlation": "exact",
        "note": "Earlier Secureworks designator"
      },
      {
        "org": "unit42",
        "name": "Fighting Ursa",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "BlueDelta",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "Sednit",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Sofacy",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Pawn Storm",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Swallowtail",
        "correlation": "exact"
      },
      {
        "org": "dragos",
        "name": "GRAPHITE",
        "correlation": "partial",
        "note": "Dragos tracks the ICS-relevant subset of Unit 26165 activity"
      },
      {
        "org": "cisa",
        "name": "GRU Unit 26165",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "GRIZZLY STEPPE",
        "correlation": "partial",
        "note": "2016 JAR umbrella covering both APT28 and APT29 — not specific to either"
      }
    ],
    "tools": [
      {
        "name": "X-Agent (CHOPSTICK)",
        "type": "backdoor",
        "custom": true,
        "description": "Modular cross-platform implant with Windows, Linux, macOS, iOS, and Android builds. Keylogging, screenshots, file exfiltration.",
        "malpediaSlug": "win.xagent"
      },
      {
        "name": "X-Tunnel",
        "type": "utility",
        "custom": true,
        "description": "Network relay used to tunnel traffic out of segmented environments; central to the DNC intrusion.",
        "malpediaSlug": "win.xtunnel"
      },
      {
        "name": "LoJax",
        "type": "malware",
        "custom": true,
        "description": "First UEFI rootkit found in the wild. Writes to SPI flash, surviving OS reinstall and disk replacement.",
        "malpediaSlug": "win.lojax"
      },
      {
        "name": "Drovorub",
        "type": "malware",
        "custom": true,
        "description": "Linux rootkit and implant with kernel module for hiding artifacts; disclosed in a joint NSA/FBI advisory.",
        "malpediaSlug": "elf.drovorub"
      },
      {
        "name": "Zebrocy",
        "type": "backdoor",
        "custom": true,
        "description": "Downloader/backdoor family rewritten across Delphi, AutoIt, C#, Go, and VB — the rewrites frustrate signature-based detection.",
        "malpediaSlug": "win.zebrocy"
      },
      {
        "name": "GooseEgg",
        "type": "utility",
        "custom": true,
        "description": "Print Spooler exploitation tool for privilege escalation and credential theft, in use since at least 2019.",
        "malpediaSlug": "win.gooseegg"
      },
      {
        "name": "HeadLace",
        "type": "backdoor",
        "custom": true,
        "description": "Multi-stage Windows backdoor delivered via geofenced landing pages, used against Ukrainian and European logistics."
      },
      {
        "name": "MASEPIE",
        "type": "backdoor",
        "custom": true,
        "description": "Python backdoor using Telegram-style API C2, deployed against Ukrainian government networks."
      },
      {
        "name": "OCEANMAP",
        "type": "backdoor",
        "custom": true,
        "description": "C# backdoor retrieving commands from IMAP mailbox drafts — blends with normal mail traffic."
      },
      {
        "name": "STEELHOOK",
        "type": "utility",
        "custom": true,
        "description": "PowerShell script that exfiltrates Chrome and Edge browser credential stores."
      },
      {
        "name": "Responder",
        "type": "lotl",
        "custom": false,
        "description": "Open-source LLMNR/NBT-NS poisoner used to capture NTLM hashes on compromised networks."
      },
      {
        "name": "Mimikatz",
        "type": "lotl",
        "custom": false,
        "description": "Credential dumping from LSASS memory."
      },
      {
        "name": "Impacket",
        "type": "lotl",
        "custom": false,
        "description": "Python SMB/DCE-RPC toolkit used for lateral movement and remote execution."
      }
    ],
    "techniques": [
      {
        "tCode": "T1589.002",
        "name": "Gather Victim Identity Information: Email Addresses",
        "tactic": "Reconnaissance",
        "note": "Extensive harvesting of defence and government mailboxes prior to campaigns"
      },
      {
        "tCode": "T1583.001",
        "name": "Acquire Infrastructure: Domains",
        "tactic": "Resource Development",
        "note": "Typosquatted webmail and SSO portals hosted on short-lived VPS"
      },
      {
        "tCode": "T1566.002",
        "name": "Phishing: Spearphishing Link",
        "tactic": "Initial Access",
        "note": "Credential harvesting pages mimicking Outlook Web Access and government SSO"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1110.003",
        "name": "Brute Force: Password Spraying",
        "tactic": "Credential Access",
        "note": "Kubernetes-based distributed brute-force cluster documented by NSA in 2021"
      },
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Roundcube and Zimbra webmail exploitation against Ukrainian and EU targets"
      },
      {
        "tCode": "T1203",
        "name": "Exploitation for Client Execution",
        "tactic": "Execution"
      },
      {
        "tCode": "T1542.001",
        "name": "Pre-OS Boot: System Firmware",
        "tactic": "Persistence",
        "note": "LoJax UEFI implant"
      },
      {
        "tCode": "T1053.005",
        "name": "Scheduled Task/Job: Scheduled Task",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1068",
        "name": "Exploitation for Privilege Escalation",
        "tactic": "Privilege Escalation",
        "note": "GooseEgg abusing Print Spooler"
      },
      {
        "tCode": "T1014",
        "name": "Rootkit",
        "tactic": "Defense Evasion",
        "note": "Drovorub kernel module on Linux"
      },
      {
        "tCode": "T1550.002",
        "name": "Use Alternate Authentication Material: Pass the Hash",
        "tactic": "Lateral Movement"
      },
      {
        "tCode": "T1187",
        "name": "Forced Authentication",
        "tactic": "Credential Access",
        "note": "CVE-2023-23397 Outlook UNC path coercion leaking Net-NTLMv2"
      },
      {
        "tCode": "T1555.003",
        "name": "Credentials from Password Stores: Credentials from Web Browsers",
        "tactic": "Credential Access",
        "note": "STEELHOOK"
      },
      {
        "tCode": "T1114.002",
        "name": "Email Collection: Remote Email Collection",
        "tactic": "Collection"
      },
      {
        "tCode": "T1071.003",
        "name": "Application Layer Protocol: Mail Protocols",
        "tactic": "Command and Control",
        "note": "OCEANMAP IMAP draft-folder C2"
      },
      {
        "tCode": "T1102.002",
        "name": "Web Service: Bidirectional Communication",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1048",
        "name": "Exfiltration Over Alternative Protocol",
        "tactic": "Exfiltration"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "Rare; primarily an influence-operations actor"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2023-23397",
        "firstExploited": "2022-04-01",
        "zeroDay": true,
        "usage": "Exploited as a zero-day for roughly eleven months before patch against government, military, energy, and transport targets in Europe. A crafted calendar invite forced Outlook to authenticate to attacker SMB infrastructure, leaking Net-NTLMv2 hashes with no user interaction at all.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Guidance for investigating attacks using CVE-2023-23397",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/",
          "date": "2023-03-24"
        }
      },
      {
        "cveId": "CVE-2022-38028",
        "firstExploited": "2019-04-01",
        "zeroDay": true,
        "usage": "Print Spooler zero-day weaponised by the GooseEgg tool for SYSTEM-level privilege escalation and credential theft. Microsoft assessed use as far back as April 2019 — over three years before patch.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Analyzing Forest Blizzard's custom post-compromise tool for exploiting CVE-2022-38028",
          "url": "https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/",
          "date": "2024-04-22"
        }
      },
      {
        "cveId": "CVE-2023-38831",
        "firstExploited": "2023-09-01",
        "usage": "WinRAR archive spoofing used to deliver credential-stealing PowerShell against Ukrainian targets, alongside several other state groups that adopted the bug within weeks of disclosure.",
        "source": {
          "org": "Google Threat Analysis Group",
          "title": "Government-backed actors exploiting WinRAR vulnerability",
          "url": "https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/",
          "date": "2023-10-18"
        }
      },
      {
        "cveId": "CVE-2020-1472",
        "firstExploited": "2020-09-01",
        "usage": "Zerologon used for rapid domain-controller compromise after establishing an initial foothold.",
        "source": {
          "org": "CISA / FBI",
          "title": "Russian State-Sponsored Advanced Persistent Threat Actor Compromises U.S. Government Targets",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-296a",
          "date": "2020-10-22"
        }
      },
      {
        "cveId": "CVE-2017-11882",
        "firstExploited": "2017-12-01",
        "usage": "Equation Editor overflow embedded in lure documents to drop Seduploader and Zebrocy.",
        "source": {
          "org": "ESET",
          "title": "Sednit update: How Fancy Bear Spent the Year",
          "url": "https://www.welivesecurity.com/2018/11/20/sednit-what-fancy-bear-spent-year/",
          "date": "2018-11-20"
        }
      },
      {
        "cveId": "CVE-2015-2545",
        "firstExploited": "2016-01-01",
        "usage": "Office EPS filter exploit used in lure documents against NATO-aligned government targets.",
        "source": {
          "org": "ESET",
          "title": "En Route with Sednit — Part 1: Approaching the Target",
          "url": "https://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part1.pdf",
          "date": "2016-10-20"
        }
      },
      {
        "cveId": "CVE-2017-0199",
        "firstExploited": "2017-04-01",
        "usage": "OLE2link RTF exploit delivering Seduploader in phishing against European government targets.",
        "source": {
          "org": "Proofpoint",
          "title": "APT28 Racing to Exploit CVE-2017-0199",
          "url": "https://www.proofpoint.com/us/threat-insight/post/apt28-racing-exploit-cve-2017-0199-office-vulnerability-before-patches",
          "date": "2017-04-20"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "sandworm",
        "type": "same-sponsor",
        "confidence": "confirmed",
        "note": "Both GRU. Charged together in the July 2018 Netyksho indictment; Unit 26165 collected, Unit 74455 ran the DCLeaks and Guccifer 2.0 leak infrastructure."
      },
      {
        "relatedActorId": "apt29",
        "type": "operational-overlap",
        "confidence": "confirmed",
        "note": "Both independently inside the DNC network in 2016 — APT29 from summer 2015, APT28 from March 2016 — apparently without deconfliction between services."
      },
      {
        "relatedActorId": "gamaredon",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both target Ukraine heavily; different services (GRU vs FSB) with occasional victim overlap."
      }
    ],
    "reports": [
      {
        "org": "CrowdStrike",
        "title": "Bears in the Midst: Intrusion into the Democratic National Committee",
        "url": "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
        "date": "2016-06-15"
      },
      {
        "org": "ESET",
        "title": "LoJax: First UEFI rootkit found in the wild, courtesy of the Sednit group",
        "url": "https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/",
        "date": "2018-09-27"
      },
      {
        "org": "NSA / FBI",
        "title": "Drovorub Malware — Russian GRU 85th GTsSS Linux Malware",
        "url": "https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF",
        "date": "2020-08-13"
      },
      {
        "org": "NSA / CISA / FBI / NCSC-UK",
        "title": "Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments",
        "url": "https://media.defense.gov/2021/Jul/01/2002753896/-1/-1/1/CSA_GRU_GLOBAL_BRUTE_FORCE_CAMPAIGN_UOO158036-21.PDF",
        "date": "2021-07-01"
      },
      {
        "org": "Recorded Future",
        "title": "BlueDelta Exploits Ukrainian Government Roundcube Mail Servers",
        "url": "https://www.recordedfuture.com/bluedelta-exploits-ukrainian-government-roundcube-mail-servers",
        "date": "2023-06-20"
      },
      {
        "org": "NSA / CISA and international partners",
        "title": "Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A)",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a",
        "date": "2025-05-21"
      }
    ],
    "campaigns": [
      {
        "id": "apt28-logistics-2025",
        "actorId": "apt28",
        "name": "Western Logistics Targeting",
        "date": "2022-03-01",
        "significance": "major",
        "targetSectors": [
          "Transportation",
          "Technology",
          "Defense",
          "Maritime"
        ],
        "targetCountries": [
          "Poland",
          "Romania",
          "Germany",
          "Ukraine",
          "Netherlands",
          "Bulgaria"
        ],
        "cveIds": [
          "CVE-2023-23397"
        ],
        "summary": "Sustained campaign against logistics providers, rail operators, ports, and air traffic entities moving aid into Ukraine, including access to border-crossing camera feeds. Documented in a 2025 advisory co-sealed by 21 agencies across 11 countries.",
        "sources": [
          {
            "org": "NSA / CISA and international partners",
            "title": "Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A)",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a",
            "date": "2025-05-21"
          }
        ]
      },
      {
        "id": "wada-opcw",
        "actorId": "apt28",
        "name": "WADA and OPCW Intrusions",
        "date": "2016-08-01",
        "endDate": "2018-04-13",
        "significance": "major",
        "targetSectors": [
          "NGO & Civil Society",
          "Government",
          "Healthcare"
        ],
        "targetCountries": [
          "Canada",
          "Switzerland",
          "Netherlands",
          "United States"
        ],
        "cveIds": [],
        "summary": "Theft and leaking of athlete medical records from the World Anti-Doping Agency after Russia's doping ban, and an attempted close-access operation against the Organisation for the Prohibition of Chemical Weapons in The Hague — run from a car in the building's car park — while it investigated the Skripal poisoning. Four GRU officers were expelled from the Netherlands.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Indictment: US v. Morenets et al.",
            "url": "https://www.justice.gov/opa/page/file/1098481/download",
            "date": "2018-10-04"
          },
          {
            "org": "Netherlands Ministry of Defence",
            "title": "Netherlands Defence Intelligence and Security Service disrupts GRU cyber operation",
            "url": "https://www.government.nl/latest/news/2018/10/04/netherlands-defence-intelligence-and-security-service-disrupts-russian-cyber-operation-targeting-opcw",
            "date": "2018-10-04"
          }
        ]
      },
      {
        "id": "dnc-2016",
        "actorId": "apt28",
        "name": "2016 U.S. Election Interference",
        "date": "2016-03-19",
        "endDate": "2016-11-08",
        "significance": "landmark",
        "targetSectors": [
          "Political Organizations",
          "Government"
        ],
        "targetCountries": [
          "United States"
        ],
        "cveIds": [],
        "summary": "Spearphishing of Democratic National Committee and campaign staff, followed by theft and staged release of internal documents through the DCLeaks and Guccifer 2.0 personas and WikiLeaks. Twelve GRU officers were later indicted by name.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Indictment: United States v. Netyksho et al.",
            "url": "https://www.justice.gov/file/1080281/download",
            "date": "2018-07-13"
          },
          {
            "org": "CrowdStrike",
            "title": "Bears in the Midst: Intrusion into the Democratic National Committee",
            "url": "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
            "date": "2016-06-15"
          }
        ]
      }
    ],
    "flag": "🇷🇺",
    "profile": "/apt/apt28/"
  }
}