- Home
- APT groups
- APT28
APT group profile
APT28
Cyberespionage group attributed by the U.S. and the UK to Unit 26165 of Russia's GRU (85th GTsSS), active since at least 2004 against governments, defense, logistics and political organizations.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
APT28 is one of the most thoroughly documented cyberespionage actors in the world. According to MITRE ATT&CK, it has operated since at least 2004 and has been attributed to the 85th Main Special Service Center (GTsSS), Military Unit 26165, of the Main Intelligence Directorate (GRU) of the Russian General Staff. That attribution was reaffirmed by the UK’s NCSC and by joint advisory AA25-141A from CISA, NSA, FBI and international partners.
Its priorities track Russia’s foreign policy and military interests: governments, armed forces, the defense industry, political organizations and, since 2022, the logistics chains supporting Ukraine. The group combines custom malware (the X-Agent/CHOPSTICK family, Zebrocy, the LoJax UEFI rootkit) with low-cost, high-volume techniques such as password spraying, exploitation of webmail and exposed services, and the use of compromised third-party infrastructure (SOHO routers). For the region, the most relevant point is that there are public reports of targets in South America, including an Ecuadorian military organization, although Europe and Ukraine remain its primary focus.
Notable campaigns
- 2022–2024 — “Nearest Neighbor”: intrusion into an organization achieved from the Wi-Fi networks of previously compromised neighboring organizations, using credentials obtained through password spraying (Volexity).
- 2022–2023 — Pawn Storm against high-value targets: brute-force attacks and Net-NTLMv2 hash relay against government, defense, energy and transportation targets in Europe, North America, South America, Asia, Africa and the Middle East (Trend Micro).
- 2022–2025 — Logistics and technology tied to aid for Ukraine: two-year campaign against defense, transportation, port, air traffic control and IT companies in a dozen NATO countries, exploiting CVE-2023-23397 (Outlook), Roundcube vulnerabilities and CVE-2023-38831 (WinRAR) (CISA AA25-141A).
- 2023–2024 — Operation RoundPress: exploitation of XSS vulnerabilities in Roundcube, Horde, MDaemon and Zimbra to steal email and credentials; ESET attributes it to Sednit with medium confidence, and among the victims it mentions government entities in South America and a military organization in Ecuador (ESET).
- 2025–2026 — DNS hijacking via SOHO routers: mass compromise of home and small-office routers to redirect DNS and mount adversary-in-the-middle attacks against Outlook on the web and Microsoft 365 (Microsoft, NCSC).
Key TTPs
Reconnaissance and initial access. APT28 frequently relies on credential harvesting via phishing links (T1598.003) and malicious Office or RAR attachments (T1566.001). It conducts slow, distributed password spraying against exposed services (T1110.003), exploits public-facing applications such as Exchange or webmail (T1190), uses external remote services through Tor and commercial VPNs (T1133) and abuses valid cloud accounts (T1078.004). The Nearest Neighbor case illustrates an uncommon vector: access via Wi-Fi networks (T1669) from compromised devices at neighboring organizations. Evil twin attacks (T1557.004) have also been documented.
Execution and persistence. It exploits client-side vulnerabilities (T1203), uses PowerShell (T1059.001) and remote template injection in Word documents (T1221). For persistence it uses Run keys (T1547.001), the “Office Test” key (T1137.002) and web shells on OWA servers (T1505.003).
Privilege escalation and credentials. It exploits local Windows kernel vulnerabilities (T1068), extracts credentials from LSASS (T1003.001) and dumps NTDS.dit via volume shadow copies (T1003.003).
Evasion, collection and C2. It deletes artifacts, for example with cipher.exe (T1070.004). It collects email from Exchange servers (T1114.002), compresses data with WinRAR (T1560.001) and communicates over HTTP/HTTPS (T1071.001), Tor/VPN proxy chains (T1090.003) and legitimate web services such as Google Drive (T1102.002), which it also uses for exfiltration (T1567).
Detection and mitigation
- Identity (priority 1). Require phishing-resistant MFA (FIDO2) for email, VPN and Microsoft 365 (M1032). In Entra ID, review sign-ins with many failures spread across many accounts from commercial VPN IPs or Tor nodes, which is the typical signature of
T1110.003. Apply smart lockout and password policies (M1027) and disable legacy authentication. - Email and webmail. Keep Roundcube, Zimbra, Horde, MDaemon and Exchange/Outlook up to date (M1051), prioritizing CVE-2023-23397. Block outbound SMB/NTLM to the Internet (TCP 445) and monitor mailbox permission changes (
Add-MailboxPermission, ApplicationImpersonation) in the Unified Audit Log. - Perimeter and routers. Inventory the SOHO routers at branch offices and remote-work sites, close their exposed management interfaces and monitor DNS/DHCP changes. Alert on DNS resolutions of corporate domains to unauthorized resolvers and on TLS certificate errors in OWA, which indicate a possible AiTM (Microsoft).
- Endpoint. Apply ASR rules to block Office child processes and macros from the Internet (M1040, M1042). Hunt for
vssadmin/ntdsutilon domain controllers, LSASS access (Sysmon EID 10),cipher.exe /wandrundll32with DLLs in user paths. Enable Credential Guard (M1043). - Corporate Wi-Fi. Require MFA or certificates (EAP-TLS) for the wireless network and correlate successful Wi-Fi authentications with physical presence, as Volexity recommends.
- Hunting in LATAM. Ministries, military forces and defense suppliers in the region should review their webmail and identity logs using these guidelines, given the South American targets reported by ESET and Trend Micro.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Malware and tools
Malware
References
Public sources this profile is based on.
- [1] APT28, Group G0007 · MITRE ATT&CK
- [2] Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A) · CISA, May 2025
- [3] UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks · NCSC (Reino Unido), Apr 2026
- [4] SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks · Microsoft Threat Intelligence, Apr 2026
- [5] Operation RoundPress · ESET, May 2025
- [6] The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access · Volexity, Nov 2024
- [7] Pawn Storm Uses Brute Force and Stealth Against High-Value Targets · Trend Micro, Jan 2024
Profile last updated: