# APT28

> As of 2026-09-19, APT28 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 25 threats spanning malware, apt, threat intel. Also known as STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON. ATT&CK coverage spans 209 techniques across 15 tactics in 25 of 25 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1005 (Data from Local System), T1041 (Exfiltration Over C2 Channel).

- **Nation:** Russia
- **Tracked threats:** 25
- **Categories:** MALWARE, APT, THREAT_INTEL, ESPIONAGE, CAMPAIGN, VULNERABILITY, PHISHING
- **Also known as:** STRONTIUM, Forest Blizzard, BRONZE PRESIDENT, CAMARO DRAGON, ClumsyToad, EARTH PRETA, FIREANT, HIVE0154, LUMINOUS MOTH, Red Lich, RedDelta, STATELY TAURUS
- **As of:** 2026-09-19

## ATT&CK techniques observed

209 techniques observed across 25 of 25 tracked threats. Tactics: Stealth (formerly Defense Evasion) (27), Credential Access (22), Resource Development (22), Collection (19), Command and Control (18), Persistence (18).

- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 18 of 25 tracked threats
- [T1005](https://attack.mitre.org/techniques/T1005/) Data from Local System — Collection — observed in 15 of 25 tracked threats
- [T1041](https://attack.mitre.org/techniques/T1041/) Exfiltration Over C2 Channel — Exfiltration — observed in 15 of 25 tracked threats
- [T1566](https://attack.mitre.org/techniques/T1566/) Phishing — Initial Access — observed in 15 of 25 tracked threats
- [T1082](https://attack.mitre.org/techniques/T1082/) System Information Discovery — Discovery — observed in 14 of 25 tracked threats
- [T1071](https://attack.mitre.org/techniques/T1071/) Application Layer Protocol — Command and Control — observed in 13 of 25 tracked threats
- [T1140](https://attack.mitre.org/techniques/T1140/) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 12 of 25 tracked threats
- [T1204](https://attack.mitre.org/techniques/T1204/) User Execution — Execution — observed in 12 of 25 tracked threats
- [T1566.001](https://attack.mitre.org/techniques/T1566/001/) Phishing: Spearphishing Attachment — Initial Access — observed in 12 of 25 tracked threats
- [T1059](https://attack.mitre.org/techniques/T1059/) Command and Scripting Interpreter — Execution — observed in 11 of 25 tracked threats
- [T1102](https://attack.mitre.org/techniques/T1102/) Web Service — Command and Control — observed in 11 of 25 tracked threats
- [T1105](https://attack.mitre.org/techniques/T1105/) Ingress Tool Transfer — Command and Control — observed in 11 of 25 tracked threats
- [T1190](https://attack.mitre.org/techniques/T1190/) Exploit Public-Facing Application — Initial Access — observed in 11 of 25 tracked threats
- [T1204.002](https://attack.mitre.org/techniques/T1204/002/) User Execution: Malicious File — Execution — observed in 11 of 25 tracked threats
- [T1071.001](https://attack.mitre.org/techniques/T1071/001/) Web Protocols — Command and Control — observed in 10 of 25 tracked threats

## Tracked threats

- [AI-Powered Polymorphic Malware Queries LLMs at Runtime to Evade Signature Detection: PROMPTFLUX and PROMPTSTEAL/LAMEHUG (APT28)](https://intel.threadlinqs.com/threat/TL-2026-2559) — MEDIUM
- [APT28-Linked HOOKEDGE Backdoor Targets Diplomatic and Government Organizations in Romania, Spain, and Türkiye](https://intel.threadlinqs.com/threat/TL-2026-2213) — HIGH
- [HOOKEDGE: New BlueDelta (APT28/Fancy Bear) Backdoor Abuses Microsoft Edge and webhook.site for C2](https://intel.threadlinqs.com/threat/TL-2026-2187) — HIGH
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — HIGH
- [Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines](https://intel.threadlinqs.com/threat/TL-2026-2058) — HIGH
- [GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors](https://intel.threadlinqs.com/threat/TL-2026-1508) — HIGH
- [Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade](https://intel.threadlinqs.com/threat/TL-2026-1497) — HIGH
- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)](https://intel.threadlinqs.com/threat/TL-2026-0745) — HIGH
- [APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)](https://intel.threadlinqs.com/threat/TL-2026-0727) — HIGH
- [Unit 42 Deep Dive: Advanced AD CS Exploitation — Certificate Template Misuse (ESC1) and Shadow Credentials via msDS-KeyCredentialLink (CVE-2022-26923, Fog Ransomware, Fighting Ursa)](https://intel.threadlinqs.com/threat/TL-2026-0497) — HIGH
- [APT28 Router DNS Hijacking for Adversary-in-the-Middle Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0330) — HIGH
- [Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain](https://intel.threadlinqs.com/threat/TL-2026-0285) — CRITICAL
- [ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools](https://intel.threadlinqs.com/threat/TL-2026-0282) — HIGH
- [Zimbra Collaboration Suite Stored XSS via CSS @import Active Exploitation (CVE-2025-66376) — Operation GhostMail](https://intel.threadlinqs.com/threat/TL-2026-0266) — CRITICAL
- [APT28 (Fancy Bear) BEARDSHELL Backdoor & COVENANT C2 Framework — Long-term Ukrainian Military Espionage Campaign (CVE-2026-21509)](https://intel.threadlinqs.com/threat/TL-2026-0204) — HIGH
- [APT28 (Fancy Bear) Deploys BadPaw Loader and MeowMeow Backdoor Targeting Ukrainian Critical Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0188) — HIGH
- [APT28 Microsoft Office Security Feature Bypass (CVE-2026-21509) — CISA KEV, Targeting Ukraine & EU via COREPER-Themed Spear-Phishing](https://intel.threadlinqs.com/threat/TL-2026-0133) — HIGH
- [RoundCube Webmail Active Exploitation — CVE-2025-49113 Deserialization RCE (CVSS 9.9) + CVE-2025-68461 XSS via SVG Animate Tag (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0130) — CRITICAL
- [Operation MacroMaze: APT28 Campaign Targeting Western & Central Europe via Evolving Macro Droppers & Legitimate Infrastructure Abuse](https://intel.threadlinqs.com/threat/TL-2026-0083) — MEDIUM
- [APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs)](https://intel.threadlinqs.com/threat/TL-2026-0066) — HIGH
- [APT28 Operation Neusploit: MS Office CVE-2026-21509 Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-0052) — CRITICAL
- [IPIDEA Residential Proxy Botnet Disruption by Google](https://intel.threadlinqs.com/threat/TL-2026-0042) — HIGH
- [CVE-2026-21509: Russian Hackers Exploit Microsoft Office Vulnerability Against Ukraine](https://intel.threadlinqs.com/threat/TL-2026-0041) — CRITICAL
- [CVE-2026-21509 - Microsoft Office Security Feature Bypass (CISA KEV)](https://intel.threadlinqs.com/threat/TL-2026-0021) — HIGH

## Related CVEs

20 CVEs referenced by tracked APT28 activity.

- [CVE-2026-32202](https://intel.threadlinqs.com/cve/CVE-2026-32202)
- [CVE-2026-21513](https://intel.threadlinqs.com/cve/CVE-2026-21513)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2025-68461](https://intel.threadlinqs.com/cve/CVE-2025-68461)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2024-27443](https://intel.threadlinqs.com/cve/CVE-2024-27443)
- [CVE-2024-11182](https://intel.threadlinqs.com/cve/CVE-2024-11182)
- [CVE-2023-50224](https://intel.threadlinqs.com/cve/CVE-2023-50224)
- [CVE-2023-43770](https://intel.threadlinqs.com/cve/CVE-2023-43770)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-23397](https://intel.threadlinqs.com/cve/CVE-2023-23397)
- [CVE-2022-26923](https://intel.threadlinqs.com/cve/CVE-2022-26923)
- [CVE-2021-44026](https://intel.threadlinqs.com/cve/CVE-2021-44026)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2020-35730](https://intel.threadlinqs.com/cve/CVE-2020-35730)
- [CVE-2020-12641](https://intel.threadlinqs.com/cve/CVE-2020-12641)
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT28
