QUIETLYTIC
Threat Actor

APT28

State-sponsored APT group targeting NATO-aligned governments, defense contractors, and critical infrastructure.

Threat Level
CRITICAL
Attribution
Russian Federation (GRU)
Also Known As
Fancy Bear, Sofacy, Pawn Storm, Sednit
Targets
Government agencies, Defense contractors, Critical infrastructure, Media organizations

Overview

APT28 (attributed to Russia’s Main Intelligence Directorate, GRU) is one of the most prolific and sophisticated threat actors targeting NATO-aligned governments and defense contractors since 2007.

Activity

APT28 maintains persistent operations against:

  • Government networks: Foreign ministries, defense departments, intelligence agencies
  • Defense contractors: Aerospace, military equipment manufacturers
  • Critical infrastructure: Energy sector, telecommunications
  • Political organizations: Think tanks, political parties, campaigns

Tactics & Techniques

  • Initial Access: Spear phishing with sophisticated social engineering
  • Persistence: Custom implants, legitimate tool abuse
  • Command & Control: Custom C2 infrastructure, DNS tunneling
  • Exfiltration: Data staging and encrypted exfil channels

Recent Activity

Q3 2026: Targeting defense contractors supporting NATO supply chains with zero-day exploits in enterprise VPN solutions. Attack chain leverages supply chain compromise of managed security providers.

IOCs

195.154.x.x (AS16276, OVH hosting, identified C2 infrastructure)
apt28[.]io (sinkholed domain)

Recommendations

  • Monitor for spear phishing from government-related entities
  • Implement strict VPN access controls and MFA
  • Hunt for unusual file transfers or data staging
  • Block known APT28 C2 domains and IPs
Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.