logo

Russia's 'Fancy Bear' APT Continues Its Global Onslaught

ID: a3e3655c-ea57-51a6-9a4f-6f307779606f

STIX ID: report--a3e3655c-ea57-51a6-9a4f-6f307779606f

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Alexander Culafi

...
...

Trend Micro and government reporting detail active operations by Fancy Bear (APT28/Pawn Storm) targeting defense and government supply chains using a Prismex malware suite (including steganography, COM hijacking, cloud abuse and wiper capabilities), NTLMv2 relay attacks exploiting CVE-2023-23397, and router-based DNS hijacking via CVE-2023-50224; the coverage includes observed targets, timelines (2022–2025+), and mitigation advice such as patching, MFA, router firmware updates, and zero trust controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.