Skip to content

APT group profile

APT28

Cyberespionage group attributed by the U.S. and the UK to Unit 26165 of Russia's GRU (85th GTsSS), active since at least 2004 against governments, defense, logistics and political organizations.

MITRE G0007 Espionage LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Reconnaissance

  • T1598.003 Phishing for Information: Spearphishing Link

Initial Access

  • T1078.004 Valid Accounts: Cloud Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1566.001 Phishing: Spearphishing Attachment
  • T1669 Wi-Fi Networks

Execution

  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1203 Exploitation for Client Execution

Persistence

  • T1137.002 Office Application Startup: Office Test
  • T1505.003 Server Software Component: Web Shell
  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Privilege Escalation

  • T1068 Exploitation for Privilege Escalation

Stealth

Credential Access

Collection

  • T1114.002 Email Collection: Remote Email Collection
  • T1560.001 Archive Collected Data: Archive via Utility

Command and Control

  • T1071.001 Application Layer Protocol: Web Protocols
  • T1090.003 Proxy: Multi-hop Proxy
  • T1102.002 Web Service: Bidirectional Communication

Exfiltration

  • T1567 Exfiltration Over Web Service

Malware and tools

References

Public sources this profile is based on.

  1. [1] APT28, Group G0007 · MITRE ATT&CK
  2. [2] Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A) · CISA, May 2025
  3. [3] UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks · NCSC (Reino Unido), Apr 2026
  4. [4] SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks · Microsoft Threat Intelligence, Apr 2026
  5. [5] Operation RoundPress · ESET, May 2025
  6. [6] The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access · Volexity, Nov 2024
  7. [7] Pawn Storm Uses Brute Force and Stealth Against High-Value Targets · Trend Micro, Jan 2024

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.