Threat Intelligence / Actor / APT28

APT28

As of 2026-09-19, APT28 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 25 threats spanning malware, apt, threat intel. Also known as STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON. ATT&CK coverage spans 209 techniques across 15 tactics in 25 of 25 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1005 (Data from Local System), T1041 (Exfiltration Over C2 Channel).

Nation: Russia · 25 tracked threat(s) · Categories: MALWARE, APT, THREAT_INTEL, ESPIONAGE, CAMPAIGN, VULNERABILITY, PHISHING

Also known as: STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON, ClumsyToad, EARTH PRETA, FIREANT, HIVE0154, LUMINOUS MOTH, Red Lich, RedDelta, STATELY TAURUS

ATT&CK techniques observed

209 techniques observed across 25 of 25 tracked threats · Stealth (formerly Defense Evasion) (27), Credential Access (22), Resource Development (22), Collection (19), Command and Control (18), Persistence (18)

Tracked threats

Related CVEs

20 CVEs referenced by tracked APT28 activity

CVE-2026-32202, CVE-2026-21513, CVE-2026-21509, CVE-2025-68461, CVE-2025-66376, CVE-2025-49113, CVE-2025-20362, CVE-2025-20333, CVE-2024-27443, CVE-2024-11182, CVE-2023-50224, CVE-2023-43770, CVE-2023-38831, CVE-2023-23397, CVE-2022-26923, CVE-2021-44026, CVE-2021-26855, CVE-2020-35730, CVE-2020-12641, CVE-2017-6742

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence