Saltar al contenido

Perfil de grupo APT

APT28

Grupo de ciberespionaje atribuido por EE. UU. y Reino Unido a la Unidad 26165 del GRU ruso (85th GTsSS), activo desde al menos 2004 contra gobiernos, defensa, logística y organismos políticos.

MITRE G0007 Espionaje LATAM Actualizado

Técnicas MITRE ATT&CK

Técnicas atribuidas al grupo en fuentes públicas, agrupadas por táctica. Cada ID enlaza a attack.mitre.org.

Reconocimiento

  • T1598.003 Phishing for Information: Spearphishing Link

Acceso inicial

  • T1078.004 Valid Accounts: Cloud Accounts
  • T1133 External Remote Services
  • T1190 Exploit Public-Facing Application
  • T1566.001 Phishing: Spearphishing Attachment
  • T1669 Wi-Fi Networks

Ejecución

  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1203 Exploitation for Client Execution

Persistencia

  • T1137.002 Office Application Startup: Office Test
  • T1505.003 Server Software Component: Web Shell
  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Escalamiento de privilegios

  • T1068 Exploitation for Privilege Escalation

Sigilo

Acceso a credenciales

Recolección

  • T1114.002 Email Collection: Remote Email Collection
  • T1560.001 Archive Collected Data: Archive via Utility

Comando y control

  • T1071.001 Application Layer Protocol: Web Protocols
  • T1090.003 Proxy: Multi-hop Proxy
  • T1102.002 Web Service: Bidirectional Communication

Exfiltración

  • T1567 Exfiltration Over Web Service

Malware y herramientas

Referencias

Fuentes públicas en las que se basa este perfil.

  1. [1] APT28, Group G0007 · MITRE ATT&CK
  2. [2] Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A) · CISA, may. 2025
  3. [3] UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks · NCSC (Reino Unido), abr. 2026
  4. [4] SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks · Microsoft Threat Intelligence, abr. 2026
  5. [5] Operation RoundPress · ESET, may. 2025
  6. [6] The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access · Volexity, nov. 2024
  7. [7] Pawn Storm Uses Brute Force and Stealth Against High-Value Targets · Trend Micro, ene. 2024

Última actualización del perfil:

¿Le preocupa este grupo?

El servicio MDR de Ventura Systems monitorea 24/7 las técnicas de este y otros actores, con caza de amenazas basada en ATT&CK.