Skip to content
RussiaState-SponsoredActiveMITRE G0007Malpedia ↗

APT28

GRU military intelligence unit behind the 2016 DNC hack, WADA and OPCW intrusions, and sustained targeting of NATO logistics.

ATTRIBUTED TORussia › GRU — Main Intelligence Directorate of the General Staff › Unit 26165

Open MITRE Navigator layer ↗Download profile JSON
Active
2004–present
Motivation
Espionage, Information Operations, Sabotage / Destruction
Aliases
16
Exploited CVEs
7
ATT&CK techniques
19
Cited sources
17

Overview

APT28 is the cyber operations arm of Russia's Main Intelligence Directorate (GRU), specifically Unit 26165 — the 85th Main Special Service Centre. It is the most thoroughly documented state hacking group in the public record, largely because the U.S. Department of Justice has twice indicted its officers by name and photograph.

The group's tradecraft is best understood as intelligence collection that accepts political risk. Where the SVR's APT29 optimises for staying unseen for years, APT28 runs high-volume credential phishing and burns infrastructure quickly. It has repeatedly crossed from collection into influence operations — stealing documents and releasing them through fronts such as DCLeaks, Guccifer 2.0, and Fancy Bears' Hack Team.

Its target set tracks Russian military and political priorities with unusual fidelity: NATO member defence ministries, European parliaments, the anti-doping bodies that banned Russian athletes, the OPCW while it investigated the Skripal poisoning, and — since February 2022 — the logistics companies, rail operators, and border-crossing systems moving aid into Ukraine.

APT28 is also a persistent innovator at the low level. In 2018 ESET documented LoJax, the first UEFI rootkit ever found in the wild, which survives both operating-system reinstallation and hard drive replacement.

Attribution

Down to the named unit where public evidence supports it.

RussiaGRU — Main Intelligence Directorate of the General StaffUnit 26165Confirmed

85th Main Special Service Centre (GTsSS), Komsomolsky Prospekt 20, Moscow

Attributed to GRU Unit 26165 by name-level U.S. federal indictment. The July 2018 Special Counsel indictment charged twelve GRU officers across Units 26165 and 74455 for the 2016 election interference operation, describing the office locations, roles, and search histories of individual officers. A second indictment in October 2018 charged seven Unit 26165 officers over the WADA, USADA, and OPCW intrusions, including close-access operations run from a parked car in The Hague. The UK NCSC, EU, and multiple NATO governments have issued concurring attributions.

Attributing sources

Cross-vendor naming crosswalk

16 designators across 13 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • APT28

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Forest BlizzardFormerly STRONTIUM, renamed April 2023
  • STRONTIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Fancy Bear

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT28

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • IRON TWILIGHT
  • TG-4127Earlier Secureworks designator

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Fighting Ursa

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • BlueDelta

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

ESET Research

index ↗
  • Sednit

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • Sofacy

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Trend Micro

index ↗
  • Pawn Storm

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

Dragos

index ↗
  • GRAPHITEpartialDragos tracks the ICS-relevant subset of Unit 26165 activity

Mineral names for groups with demonstrated or assessed intent against industrial control systems. A Dragos designator is a meaningful signal: it means OT/ICS capability, not just IT intrusion.

Symantec (Broadcom)

index ↗
  • Swallowtail

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • GRU Unit 26165
  • GRIZZLY STEPPEpartial2016 JAR umbrella covering both APT28 and APT29 — not specific to either

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUkraineGermanyFrancePolandUnited KingdomNorwayNetherlandsCzechiaGeorgiaTürkiye

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

X-Agent (CHOPSTICK)backdoor

Modular cross-platform implant with Windows, Linux, macOS, iOS, and Android builds. Keylogging, screenshots, file exfiltration.

Malpedia ↗
X-Tunnelutility

Network relay used to tunnel traffic out of segmented environments; central to the DNC intrusion.

Malpedia ↗
LoJaxmalware

First UEFI rootkit found in the wild. Writes to SPI flash, surviving OS reinstall and disk replacement.

Malpedia ↗
Drovorubmalware

Linux rootkit and implant with kernel module for hiding artifacts; disclosed in a joint NSA/FBI advisory.

Malpedia ↗
Zebrocybackdoor

Downloader/backdoor family rewritten across Delphi, AutoIt, C#, Go, and VB — the rewrites frustrate signature-based detection.

Malpedia ↗
GooseEggutility

Print Spooler exploitation tool for privilege escalation and credential theft, in use since at least 2019.

Malpedia ↗
HeadLacebackdoor

Multi-stage Windows backdoor delivered via geofenced landing pages, used against Ukrainian and European logistics.

MASEPIEbackdoor

Python backdoor using Telegram-style API C2, deployed against Ukrainian government networks.

OCEANMAPbackdoor

C# backdoor retrieving commands from IMAP mailbox drafts — blends with normal mail traffic.

STEELHOOKutility

PowerShell script that exfiltrates Chrome and Edge browser credential stores.

Shared, commodity & living-off-the-land

Responderlotl

Open-source LLMNR/NBT-NS poisoner used to capture NTLM hashes on compromised networks.

Mimikatzlotl

Credential dumping from LSASS memory.

Impacketlotl

Python SMB/DCE-RPC toolkit used for lateral movement and remote execution.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT28
CVE-2023-38831KEVransomware7.81 Sep 2023WinRAR archive spoofing used to deliver credential-stealing PowerShell against Ukrainian targets, alongside several other state groups that adopted the bug within weeks of disclosure.SRCGoogle Threat Analysis Group
CVE-2023-233970-dayKEV9.81 Apr 2022Exploited as a zero-day for roughly eleven months before patch against government, military, energy, and transport targets in Europe. A crafted calendar invite forced Outlook to authenticate to attacker SMB infrastructure, leaking Net-NTLMv2 hashes with no user interaction at all.SRCMicrosoft Threat Intelligence
CVE-2020-1472KEVransomware10.01 Sep 2020Zerologon used for rapid domain-controller compromise after establishing an initial foothold.SRCCISA / FBI
CVE-2022-380280-dayKEV7.81 Apr 2019Print Spooler zero-day weaponised by the GooseEgg tool for SYSTEM-level privilege escalation and credential theft. Microsoft assessed use as far back as April 2019 — over three years before patch.SRCMicrosoft Threat Intelligence
CVE-2017-11882KEVransomware7.81 Dec 2017Equation Editor overflow embedded in lure documents to drop Seduploader and Zebrocy.SRCESET
CVE-2017-0199KEVransomware7.81 Apr 2017OLE2link RTF exploit delivering Seduploader in phishing against European government targets.SRCProofpoint
CVE-2015-2545KEV7.81 Jan 2016Office EPS filter exploit used in lure documents against NATO-aligned government targets.SRCESET

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

13 stages · 19 techniques
  1. 02

    Resource Development

    1 technique

    Registers typosquatted webmail and SSO portals on short-lived VPS, burning and replacing them faster than blocklists propagate.

  2. 06

    Privilege Escalation

    1 technique

    GooseEgg exploits Print Spooler for SYSTEM, a capability Microsoft assessed the group had been running since 2019 — more than three years before the flaw was patched.

  3. 07

    Defense Evasion

    1 technique

    Persists below the operating system where necessary. LoJax writes to SPI flash and survives disk replacement; Drovorub hides its own artifacts from a running Linux kernel.

  4. 10

    Collection

    1 technique

    Mailboxes and documents from the specific offices — a defence ministry, an anti-doping laboratory, a rail operator moving aid — whose contents serve the operation's political objective.

  5. 12

    Exfiltration

    1 technique

    Staged out over alternative protocols, then frequently published — through DCLeaks, Guccifer 2.0, or Fancy Bears' Hack Team — because for this actor the leak, not the collection, is often the objective.

  6. 13

    Impact

    1 technique

    Rare. Where APT28 causes effect it is informational rather than destructive; the GRU's disruptive work belongs to Unit 74455.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
19 techniques across 13 tactics · 12 with actor-specific notes

Reconnaissance

1

Resource Development

1

Initial Access

3

Privilege Escalation

1

Defense Evasion

1

Credential Access

3

Impact

1

Campaign timeline

  1. Western Logistics Targeting

    Sustained campaign against logistics providers, rail operators, ports, and air traffic entities moving aid into Ukraine, including access to border-crossing camera feeds. Documented in a 2025 advisory co-sealed by 21 agencies across 11 countries.

    CVE-2023-23397TransportationTechnologyDefenseMaritime
  2. WADA and OPCW Intrusions

    Theft and leaking of athlete medical records from the World Anti-Doping Agency after Russia's doping ban, and an attempted close-access operation against the Organisation for the Prohibition of Chemical Weapons in The Hague — run from a car in the building's car park — while it investigated the Skripal poisoning. Four GRU officers were expelled from the Netherlands.

    NGO & Civil SocietyGovernmentHealthcare
  3. landmark

    2016 U.S. Election Interference

    Spearphishing of Democratic National Committee and campaign staff, followed by theft and staged release of internal documents through the DCLeaks and Guccifer 2.0 personas and WikiLeaks. Twelve GRU officers were later indicted by name.

    Political OrganizationsGovernment

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.