Threat Actor 🇷🇺 Russia

APT28

Also known as: Pawn Storm · FANCY BEAR · Sednit · SNAKEMACKEREL · Tsar Team · TG-4127 · STRONTIUM · Swallowtail · IRON TWILIGHT · Group 74 · SIG40 · Grizzly Steppe · G0007 · ATK5 · Fighting Ursa · ITG05 · Blue Athena · TA422 · T-APT-12 · APT-C-20 · UAC-0028 · UAC-0001 · FROZENLAKE · Sofacy · Forest Blizzard · BlueDelta · Fancy Bear · GruesomeLarch

The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and security organizations. It has been characterized as an advanced persistent threat.

Indicators of Compromise 13

MITRE ATT&CK TTPs 17

Source Articles

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A threat actor dubbed Storm-2945, assessed to be a sub-cluster of the Russian state-sponsored group APT29 (aka Cozy Bear), has hijacked hotel Wi-Fi networks to deliver a surveillance-focused remote access trojan named CornFlake. The attack abuses compromised captive portals to redirect users to fake browser or OS update prompts, which lead to the download of malicious payloads. The CornFlake malware, written in Go, establishes persistence via registry run keys and scheduled tasks, captures keystrokes, screenshots, microphone audio, and browser credentials, and can bypass Chrome's App-Bound Encryption. A related in-memory PowerShell stealer, ChocoShell, harvests Microsoft 365, Azure AD, and WAM tokens from the Token Broker cache. Attackers also leveraged Microsoft's device code authentication flow to gain MFA-satisfied access by tricking users into approving malicious sessions.
hacker-news ·4w ago
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.
bleeping-computer ·1mo ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news ·1mo ago
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the US and allied nations have issued a joint advisory warning of Russian state-sponsored hackers, attributed to FSB Center 16, targeting critical infrastructure by exploiting misconfigured routers and known vulnerabilities. The threat actor scans for devices using default SNMP credentials and exploits CVE-2018-0171 in Cisco Smart Install to gain control of network devices. Sectors at risk include energy, healthcare, defense, and government services. The advisory emphasizes mitigation steps such as disabling vulnerable features, upgrading to SNMPv3, and blocking unauthorized protocols at firewalls.
bleeping-computer ·1mo ago
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer ·1mo ago