APT28
As of 2026-09-19, APT28 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 25 threats spanning malware, apt, threat intel. Also known as STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON. ATT&CK coverage spans 209 techniques across 15 tactics in 25 of 25 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1005 (Data from Local System), T1041 (Exfiltration Over C2 Channel).
Also known as: STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON, ClumsyToad, EARTH PRETA, FIREANT, HIVE0154, LUMINOUS MOTH, Red Lich, RedDelta, STATELY TAURUS
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 18 of 25 tracked threats
- T1005 Data from Local System — Collection — observed in 15 of 25 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 15 of 25 tracked threats
- T1566 Phishing — Initial Access — observed in 15 of 25 tracked threats
- T1082 System Information Discovery — Discovery — observed in 14 of 25 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 13 of 25 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 12 of 25 tracked threats
- T1204 User Execution — Execution — observed in 12 of 25 tracked threats
- T1566.001 Phishing: Spearphishing Attachment — Initial Access — observed in 12 of 25 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 11 of 25 tracked threats
- T1102 Web Service — Command and Control — observed in 11 of 25 tracked threats
- T1105 Ingress Tool Transfer — Command and Control — observed in 11 of 25 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 11 of 25 tracked threats
- T1204.002 User Execution: Malicious File — Execution — observed in 11 of 25 tracked threats
- T1071.001 Web Protocols — Command and Control — observed in 10 of 25 tracked threats
Tracked threats
- AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28) — MEDIUM
- APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye — HIGH
- HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2 — HIGH
- BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor — HIGH
- Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines — HIGH
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors — HIGH
- Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade — HIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise — MEDIUM
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855) — HIGH
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509) — HIGH
- Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials via msDS-KeyCredentialLink (CVE-2022-26923, Fog Ransomware, Fighting Ursa) — HIGH
- APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft — HIGH
- Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain — CRITICAL
- ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools — HIGH
- Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail — CRITICAL
- APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509) — HIGH
- APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure — HIGH
- APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing — HIGH
- RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS via SVG Animate Tag (CISA KEV) — CRITICAL
- Operation MacroMaze: APT28 Campaign Targeting Western & Central Europe via Evolving Macro Droppers & Legitimate Infrastructure Abuse — MEDIUM
- APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs) — HIGH
- APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign — CRITICAL
- IPIDEA Residential Proxy Botnet Disruption by Google — HIGH
- CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine — CRITICAL
- CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV) — HIGH
Related CVEs
CVE-2026-32202, CVE-2026-21513, CVE-2026-21509, CVE-2025-68461, CVE-2025-66376, CVE-2025-49113, CVE-2025-20362, CVE-2025-20333, CVE-2024-27443, CVE-2024-11182, CVE-2023-50224, CVE-2023-43770, CVE-2023-38831, CVE-2023-23397, CVE-2022-26923, CVE-2021-44026, CVE-2021-26855, CVE-2020-35730, CVE-2020-12641, CVE-2017-6742