APT28: An Evolution of Tradecraft from X-Agent to LLM Malware
ID: 35ea4330-09ae-5c02-b43a-62196b529c75
STIX ID: report--35ea4330-09ae-5c02-b43a-62196b529c75
Feed Name: Sekoia.com
**Executive summary:** Sekoia TDR presents a two-decade overview of APT28 (Fancy Bear) detailing how the group evolved from monolithic implants (X-Agent/X-Tunnel) to disposable single-purpose components and back to a modern in-house implant chain, while adopting large-scale infrastructure abuse of compromised SOHO routers, exploiting zero-click and privilege‑escalation vulnerabilities, and experimenting with an LLM-driven infostealer, affecting governments, NATO-related entities, Ukrainian civil society, and thousands of consumer and organizational devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
