Threat Actor 🇷🇺 Russia
APT28
Also known as: Pawn Storm · FANCY BEAR · Sednit · SNAKEMACKEREL · Tsar Team · TG-4127 · STRONTIUM · Swallowtail · IRON TWILIGHT · Group 74 · SIG40 · Grizzly Steppe · G0007 · ATK5 · Fighting Ursa · ITG05 · Blue Athena · TA422 · T-APT-12 · APT-C-20 · UAC-0028 · UAC-0001 · FROZENLAKE · Sofacy · Forest Blizzard · BlueDelta · Fancy Bear · GruesomeLarch
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and security organizations. It has been characterized as an advanced persistent threat.
Indicators of Compromise 13
Domain apt28-c2[.]info Domain cl-sta-1114[.]org Domain laundrybear-c2[.]com Domain m365-owa[.]com Domain ms365-device[.]com Domain ms365-live[.]com Domain owa-ms365[.]com Domain protonmail-c2[.]com Domain seqrite-c2[.]org Domain ta488-c2[.]xyz Domain voidblizzard-c2[.]net Domain zimbrastolen[.]net Domain zimreaper-exfil[.]com
MITRE ATT&CK TTPs 11
T1027 T1055 T1059.001 T1071.004 T1078.004 T1090 T1114 T1204.002 T1556.005 T1558.003 T1566
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
DNS
Command And Control
Cloud Accounts
Defense Evasion
Proxy
Command And Control
Email Collection
Collection
Malicious File
Execution
Reversible Encryption
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Source Articles
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.
bleeping-computer ·3d ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news ·4d ago
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the US and allied nations have issued a joint advisory warning of Russian state-sponsored hackers, attributed to FSB Center 16, targeting critical infrastructure by exploiting misconfigured routers and known vulnerabilities. The threat actor scans for devices using default SNMP credentials and exploits CVE-2018-0171 in Cisco Smart Install to gain control of network devices. Sectors at risk include energy, healthcare, defense, and government services. The advisory emphasizes mitigation steps such as disabling vulnerable features, upgrading to SNMPv3, and blocking unauthorized protocols at firewalls.
bleeping-computer ·2w ago
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer ·2w ago