APT · Russia
State-sponsored group targeting government, defense, and media organizations with spear-phishing and credential theft campaigns.
Псевдонимы: Fancy Bear, Sofacy, STRONTIUM
Мотивация: Espionage and geopolitical influence
Ликвидация инцидента
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.
Разведка
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Требование выкупа
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Разведка
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.
Первичный доступ
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Ликвидация инцидента
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Повышение привилегий
Field telemetry from Washington DC correlates with LockBit Affiliates Hit Major US Hospital Network.
Разведка
Field telemetry from Amsterdam correlates with FIN7 Uses AI-Generated Voice Deepfakes in Vishing Attacks.
Первичный доступ
Field telemetry from Beijing correlates with APT28 Phishing Campaign Impersonates Ukrainian Government.