APT28, an evolution of tradecraft
ID: 8165d61c-408a-5d15-8e1f-adb99f8b941e
STIX ID: report--8165d61c-408a-5d15-8e1f-adb99f8b941e
Feed Name: Sekoia.io Blog (archive)
Sekoia TDR presents a two-decade review of APT28 (Fancy Bear), documenting an evolution from monolithic implants (X-Agent/X-Tunnel) and hack-and-leak operations to fragmented disposable tooling, large-scale edge-device compromise (MooBot, FrostArmada), credential-harvesting campaigns against Ukrainian civil society (including RoundPress and UKR.NET targeting), exploitation of known CVEs (e.g., CVE-2023-23397, CVE-2022-38028), a re-emergence of in-house implants (BeardShell, Slimagent, Covenant-backed chains) using abused legitimate cloud services for C2, and a proof-of-concept LLM-integrated infostealer (LameHug); the report highlights high sophistication, extensive targeting of governments and critical infrastructure, and ongoing law-enforcement disruption efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
