logo

Russian APT28 Hackers Targeting High-Value Orgs with NTLM Relay Attacks

ID: 5e6198e0-6727-55a5-bead-522ccf088b12

STIX ID: report--5e6198e0-6727-55a5-bead-522ccf088b12

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

APT28 (Fancy Bear), a Russian GRU-linked threat actor, conducted widespread NTLMv2 hash relays, credential-harvesting phishing, and exploitation of high-severity vulnerabilities (notably CVE-2023-23397) from April 2022 to Nov 2023 against government and critical-sector organizations worldwide, employing anonymization (VPN/Tor, data-center IPs, compromised EdgeOS routers), bespoke malware (HeadLace, OCEANMAP, MASEPIE, STEELHOOK), and mailbox persistence to enable lateral movement and large-scale compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.