Reconnaissance
1 technique
Harvests defence, government and logistics mailboxes at scale ahead of a campaign — the target list is assembled before any infrastructure is stood up.
GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.
ATTRIBUTED TORussia › GRU — Main Intelligence Directorate of the General Staff › Unit 26165
APT28 is the cyber operations arm of Russia's Main Intelligence Directorate (GRU), specifically Unit 26165 — the 85th Main Special Service Centre. It is the most thoroughly documented state hacking group in the public record, largely because the U.S. Department of Justice has twice indicted its officers by name and photograph.
The group's tradecraft is best understood as intelligence collection that accepts political risk. Where the SVR's APT29 optimises for staying unseen for years, APT28 runs high-volume credential phishing and burns infrastructure quickly. It has repeatedly crossed from collection into influence operations — stealing documents and releasing them through fronts such as DCLeaks, Guccifer 2.0, and Fancy Bears' Hack Team.
Its target set tracks Russian military and political priorities with unusual fidelity: NATO member defence ministries, European parliaments, the anti-doping bodies that banned Russian athletes, the OPCW while it investigated the Skripal poisoning, and — since February 2022 — the logistics companies, rail operators, and border-crossing systems moving aid into Ukraine.
APT28 is also a persistent innovator at the low level. In 2018 ESET documented LoJax, the first UEFI rootkit ever found in the wild, which survives both operating-system reinstallation and hard drive replacement.
Down to the named unit where public evidence supports it.
85th Main Special Service Centre (GTsSS), Komsomolsky Prospekt 20, Moscow
Attributed to GRU Unit 26165 by name-level U.S. federal indictment. The July 2018 Special Counsel indictment charged twelve GRU officers across Units 26165 and 74455 for the 2016 election interference operation, describing the office locations, roles, and search histories of individual officers. A second indictment in October 2018 charged seven Unit 26165 officers over the WADA, USADA, and OPCW intrusions, including close-access operations run from a parked car in The Hague. The UK NCSC, EU, and multiple NATO governments have issued concurring attributions.
Attributing sources
16 designators across 13 organisations.
2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, frequently derived from the group's flagship malware family.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Modular cross-platform implant with Windows, Linux, macOS, iOS, and Android builds. Keylogging, screenshots, file exfiltration.
Malpedia ↗Network relay used to tunnel traffic out of segmented environments; central to the DNC intrusion.
Malpedia ↗First UEFI rootkit found in the wild. Writes to SPI flash, surviving OS reinstall and disk replacement.
Malpedia ↗Linux rootkit and implant with kernel module for hiding artifacts; disclosed in a joint NSA/FBI advisory.
Malpedia ↗Downloader/backdoor family rewritten across Delphi, AutoIt, C#, Go, and VB — the rewrites frustrate signature-based detection.
Malpedia ↗Print Spooler exploitation tool for privilege escalation and credential theft, in use since at least 2019.
Malpedia ↗Multi-stage Windows backdoor delivered via geofenced landing pages, used against Ukrainian and European logistics.
Python backdoor using Telegram-style API C2, deployed against Ukrainian government networks.
C# backdoor retrieving commands from IMAP mailbox drafts — blends with normal mail traffic.
PowerShell script that exfiltrates Chrome and Edge browser credential stores.
Shared, commodity & living-off-the-land
Open-source LLMNR/NBT-NS poisoner used to capture NTLM hashes on compromised networks.
Credential dumping from LSASS memory.
Python SMB/DCE-RPC toolkit used for lateral movement and remote execution.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT28 | ||
|---|---|---|---|---|
| CVE-2023-38831KEVransomware | 7.8 | WinRARRARLAB | 1 Sep 2023 | WinRAR archive spoofing used to deliver credential-stealing PowerShell against Ukrainian targets, alongside several other state groups that adopted the bug within weeks of disclosure.SRCGoogle Threat Analysis Group ↗ |
| CVE-2023-233970-dayKEV | 9.8 | Microsoft OutlookMicrosoft | 1 Apr 2022 | Exploited as a zero-day for roughly eleven months before patch against government, military, energy, and transport targets in Europe. A crafted calendar invite forced Outlook to authenticate to attacker SMB infrastructure, leaking Net-NTLMv2 hashes with no user interaction at all.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2020-1472KEVransomware | 10.0 | Windows NetlogonMicrosoft | 1 Sep 2020 | Zerologon used for rapid domain-controller compromise after establishing an initial foothold.SRCCISA / FBI ↗ |
| CVE-2022-380280-dayKEV | 7.8 | Windows Print SpoolerMicrosoft | 1 Apr 2019 | Print Spooler zero-day weaponised by the GooseEgg tool for SYSTEM-level privilege escalation and credential theft. Microsoft assessed use as far back as April 2019 — over three years before patch.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Dec 2017 | Equation Editor overflow embedded in lure documents to drop Seduploader and Zebrocy.SRCESET ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Apr 2017 | OLE2link RTF exploit delivering Seduploader in phishing against European government targets.SRCProofpoint ↗ |
| CVE-2015-2545KEV | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2016 | Office EPS filter exploit used in lure documents against NATO-aligned government targets.SRCESET ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique
Harvests defence, government and logistics mailboxes at scale ahead of a campaign — the target list is assembled before any infrastructure is stood up.
1 technique
Registers typosquatted webmail and SSO portals on short-lived VPS, burning and replacing them faster than blocklists propagate.
3 techniques
Two modes, run in parallel. Credential phishing against Outlook Web Access and government SSO for volume, and genuine zero-day exploitation when a target justifies it — CVE-2023-23397 required no user interaction at all, leaking the credential hash the moment the message arrived.
1 technique·derived
Exploitation for Client Execution.
2 techniques
Scheduled tasks on Windows, firmware on the machines that matter.
1 technique
GooseEgg exploits Print Spooler for SYSTEM, a capability Microsoft assessed the group had been running since 2019 — more than three years before the flaw was patched.
1 technique
Persists below the operating system where necessary. LoJax writes to SPI flash and survives disk replacement; Drovorub hides its own artifacts from a running Linux kernel.
3 techniques
Coerces authentication rather than asking for it. A UNC path in a calendar invite forces Outlook to authenticate to attacker SMB infrastructure; a Kubernetes cluster sprays passwords across cloud tenants at industrial scale.
1 technique
Pass-the-hash using the Net-NTLMv2 material gathered during forced authentication, so movement continues without ever cracking a password.
1 technique
Mailboxes and documents from the specific offices — a defence ministry, an anti-doping laboratory, a rail operator moving aid — whose contents serve the operation's political objective.
2 techniques
OCEANMAP retrieves commands from IMAP mailbox drafts, so C2 is indistinguishable from a user's own mail client synchronising.
1 technique
Staged out over alternative protocols, then frequently published — through DCLeaks, Guccifer 2.0, or Fancy Bears' Hack Team — because for this actor the leak, not the collection, is often the objective.
1 technique
Rare. Where APT28 causes effect it is informational rather than destructive; the GRU's disruptive work belongs to Unit 74455.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Extensive harvesting of defence and government mailboxes prior to campaigns
Typosquatted webmail and SSO portals hosted on short-lived VPS
Credential harvesting pages mimicking Outlook Web Access and government SSO
Roundcube and Zimbra webmail exploitation against Ukrainian and EU targets
GooseEgg abusing Print Spooler
Drovorub kernel module on Linux
Kubernetes-based distributed brute-force cluster documented by NSA in 2021
CVE-2023-23397 Outlook UNC path coercion leaking Net-NTLMv2
STEELHOOK
OCEANMAP IMAP draft-folder C2
Rare; primarily an influence-operations actor
Sustained campaign against logistics providers, rail operators, ports, and air traffic entities moving aid into Ukraine, including access to border-crossing camera feeds. Documented in a 2025 advisory co-sealed by 21 agencies across 11 countries.
Theft and leaking of athlete medical records from the World Anti-Doping Agency after Russia's doping ban, and an attempted close-access operation against the Organisation for the Prohibition of Chemical Weapons in The Hague — run from a car in the building's car park — while it investigated the Skripal poisoning. Four GRU officers were expelled from the Netherlands.
Spearphishing of Democratic National Committee and campaign staff, followed by theft and staged release of internal documents through the DCLeaks and Guccifer 2.0 personas and WikiLeaks. Twelve GRU officers were later indicted by name.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both GRU. Charged together in the July 2018 Netyksho indictment; Unit 26165 collected, Unit 74455 ran the DCLeaks and Guccifer 2.0 leak infrastructure.
Both independently inside the DNC network in 2016 — APT29 from summer 2015, APT28 from March 2016 — apparently without deconfliction between services.
Both target Ukraine heavily; different services (GRU vs FSB) with occasional victim overlap.
Curated links to the reports that established what is known about this group.