Overview
The APT28 Nearest Neighbor Campaign (MITRE ATT&CK ID C0051) was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine, per MITRE’s campaign profile. MITRE documents APT28 primarily relying on living-off-the-land techniques while also exploiting a zero-day vulnerability, CVE-2022-38028. The campaign’s most distinctive element, per MITRE’s citations, was its initial access method: APT28 used Wi-Fi networks in close physical proximity to its intended target, daisy-chaining through multiple already-compromised organizations nearby until it found a dual-homed system — one with both a wired and wireless network connection — to bridge from a compromised Wi-Fi network into the actual target’s wired network using stolen credentials.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from February 2022 to November 2024.
Actors involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to APT28, consistent with the group’s documented GRU-linked focus on organizations connected to Ukraine. MITRE’s relationship data lists use of built-in Windows utilities — including netsh and cipher.exe — rather than custom malware for much of the campaign, consistent with the living-off-the-land approach the overview describes.
What we don’t have
MITRE’s data doesn’t specify how APT28 initially gained a foothold in the first “nearest neighbor” organization in each chain, only the technique used to pivot from it. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no confirmation of the total number of organizations daisy-chained together in any single documented intrusion.
Frequently Asked Questions
What was the APT28 Nearest Neighbor Campaign? A campaign, per MITRE ATT&CK, in which APT28 reached targets by compromising nearby Wi-Fi-connected organizations and pivoting through dual-homed systems into the intended victim’s wired network, active February 2022 to November 2024.
Why is the “nearest neighbor” technique notable? It let APT28 gain network access without ever directly compromising the intended target’s own internet-facing infrastructure — the initial breach happened in a physically nearby but otherwise unrelated organization, per MITRE’s citations.
What vulnerability did APT28 exploit in this campaign? CVE-2022-38028, exploited as a zero-day, per MITRE’s documentation.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0051, aggregated September 20, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.