APT28
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Sednit, also tracked as APT28, Fancy Bear, Sofacy, Strontium and BlueDelta, is a threat actor publicly linked to Russia’s General Staff Main Intelligence Directorate (GRU) and described in multiple sources as a state‑sponsored hacking group. The actor’s observed targeting spans governmental, military, energy and transportation sectors across Europe and the United States, with a recurring focus on Ukrainian governmental entities and NATO‑aligned organizations. Public attributions consistently describe the actor’s strategic objectives as cyber‑espionage aimed at gathering military, diplomatic and political intelligence to support Russian state interests, rather than financially motivated crime.
The actor’s reported tactics include the use of spear‑phishing emails that lure recipients with topical news about the Russia‑Ukraine conflict, the exploitation of specific software vulnerabilities such as CVE‑2020‑35730, CVE‑2020‑12641 and CVE‑2021‑44026 in Roundcube webmail, and the exploitation of a Microsoft Outlook zero‑day (CVE‑2023‑23397) to steal credentials and manipulate mailbox permissions for lateral movement. Additional techniques observed involve brute‑force and password‑spray attacks, the use of Tor‑anchored infrastructure to obfuscate command‑and‑control traffic, and the deployment of custom malware named Jaguar Tooth on Cisco IOS routers via an SNMP flaw (CVE‑2017‑6742) to gain unauthenticated backdoor access and exfiltrate device configuration data. The actor has also been seen delivering malicious scripts after compromising email servers that redirect victims’ incoming mail to attacker‑controlled addresses, enabling reconnaissance and the theft of address books, session cookies and other data stored within Roundcube databases.
Representative campaigns cited in the source material include the 2015 intrusion into the German Federal Parliament (Deutscher Bundestag) and the 2016 compromises of the Democratic National Committee and Democratic Congressional Campaign Committee, for which U.S. authorities later issued charges. More recent operations involve a 2023 campaign against Ukrainian government email servers that leveraged the aforementioned Roundcube vulnerabilities to harvest military intelligence in support of Russia’s invasion of Ukraine, a 2023 intrusion campaign exploiting the Outlook zero‑day to breach government, military, energy and transportation organizations across Europe, and a 2023 operation in which Jaguar Tooth malware was deployed on Cisco routers to harvest intelligence from U.S. and EU‑based targets. The actor’s infrastructure for these activities has been observed operational since at least November 2021, and the Council of the European Union formally sanctioned individuals associated with the group in October 2020 for their role in the 2015 Bundestag breach. This synthesis reflects only the facts explicitly presented in the supplied material.
Incidents
Attributed incidents are available to members.
142 incidents