APT · Russia
State-sponsored group targeting government, defense, and media organizations with spear-phishing and credential theft campaigns.
Aliases: Fancy Bear, Sofacy, STRONTIUM
Motivation: Espionage and geopolitical influence
Resolution
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.
Reconnaissance
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Ransom Demand
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Reconnaissance
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.
Initial Access
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Resolution
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Privilege Escalation
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Reconnaissance
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Initial Access
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.