logo

APT28 Cyber Espionage Campaign Targets French Institutions Since 2021

ID: 4ff68191-9997-518a-a8ee-ad3e258672fc

STIX ID: report--4ff68191-9997-518a-a8ee-ad3e258672fc

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

ANSSI describes a sustained APT28 (Fancy Bear) espionage campaign since 2021 targeting French and European governmental, diplomatic, defence, research and industrial organizations using phishing, brute-force webmail attacks, exploitation of known vulnerabilities (e.g., CVE-2023-23397), and commodity/outsourced infrastructure (Mocky.IO, InfinityFree) to deliver malware families including HeadLace, OceanMap (an IMAP-based stealer), SteelHook and MasePie, often focused on rapid data exfiltration rather than long-term persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.