Dark Web Profile: APT28
ID: f319864c-32a9-5de4-8ca1-a98a3a41099d
STIX ID: report--f319864c-32a9-5de4-8ca1-a98a3a41099d
Feed Name: SOCRadar Blog
APT28 (Fancy Bear / Sofacy) is a long-running GRU-linked espionage actor active since the mid-2000s and continuing operations into 2024–2025; the profile details its intelligence-driven targeting (governments, defense, NATO-linked organizations, logistics and aid providers for Ukraine), common techniques (spearphishing, credential/token theft, exploitation of public-facing apps, abuse of native tools like PowerShell), notable campaigns (including the 2025 LAMEHUG AI-assisted malware and widespread credential-harvesting against email/cloud accounts), and mitigation recommendations with MITRE ATT&CK mappings to help defenders detect and respond.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
