logo

Dark Web Profile: APT28

ID: f319864c-32a9-5de4-8ca1-a98a3a41099d

STIX ID: report--f319864c-32a9-5de4-8ca1-a98a3a41099d

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-01-20

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

APT28 (Fancy Bear / Sofacy) is a long-running GRU-linked espionage actor active since the mid-2000s and continuing operations into 2024–2025; the profile details its intelligence-driven targeting (governments, defense, NATO-linked organizations, logistics and aid providers for Ukraine), common techniques (spearphishing, credential/token theft, exploitation of public-facing apps, abuse of native tools like PowerShell), notable campaigns (including the 2025 LAMEHUG AI-assisted malware and widespread credential-harvesting against email/cloud accounts), and mitigation recommendations with MITRE ATT&CK mappings to help defenders detect and respond.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.