Threat Actor 🇷🇺 Russia
APT28
Also known as: Pawn Storm · FANCY BEAR · Sednit · SNAKEMACKEREL · Tsar Team · TG-4127 · STRONTIUM · Swallowtail · IRON TWILIGHT · Group 74 · SIG40 · Grizzly Steppe · G0007 · ATK5 · Fighting Ursa · ITG05 · Blue Athena · TA422 · T-APT-12 · APT-C-20 · UAC-0028 · UAC-0001 · FROZENLAKE · Sofacy · Forest Blizzard · BlueDelta · Fancy Bear · GruesomeLarch
The Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and security organizations. It has been characterized as an advanced persistent threat.
Indicators of Compromise 13
Domain apt28-c2[.]info Domain cl-sta-1114[.]org Domain laundrybear-c2[.]com Domain m365-owa[.]com Domain ms365-device[.]com Domain ms365-live[.]com Domain owa-ms365[.]com Domain protonmail-c2[.]com Domain seqrite-c2[.]org Domain ta488-c2[.]xyz Domain voidblizzard-c2[.]net Domain zimbrastolen[.]net Domain zimreaper-exfil[.]com
MITRE ATT&CK TTPs 17
T1003 T1027 T1053.005 T1055 T1059.001 T1070.004 T1071.001 T1071.004 T1078.004 T1090 T1114 T1136.001 T1204.002 T1556.005 T1558 T1558.003 T1566
OS Credential Dumping
Credential Access
Obfuscated Files or Information
Defense Evasion
Scheduled Task
Execution
Process Injection
Defense Evasion
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
DNS
Command And Control
Cloud Accounts
Defense Evasion
Proxy
Command And Control
Email Collection
Collection
Local Account
Persistence
Malicious File
Execution
Reversible Encryption
Credential Access
Steal or Forge Kerberos Tickets
Credential Access
Kerberoasting
Credential Access
Phishing
Initial Access
Source Articles
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
A threat actor dubbed Storm-2945, assessed to be a sub-cluster of the Russian state-sponsored group APT29 (aka Cozy Bear), has hijacked hotel Wi-Fi networks to deliver a surveillance-focused remote access trojan named CornFlake. The attack abuses compromised captive portals to redirect users to fake browser or OS update prompts, which lead to the download of malicious payloads. The CornFlake malware, written in Go, establishes persistence via registry run keys and scheduled tasks, captures keystrokes, screenshots, microphone audio, and browser credentials, and can bypass Chrome's App-Bound Encryption. A related in-memory PowerShell stealer, ChocoShell, harvests Microsoft 365, Azure AD, and WAM tokens from the Token Broker cache. Attackers also leveraged Microsoft's device code authentication flow to gain MFA-satisfied access by tricking users into approving malicious sessions.
hacker-news ·4w ago
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are hijacking hotel and conference center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages, enabling theft of credentials and bypassing multi-factor authentication via OAuth token authorization. The campaign, active since at least June 2026, targets traveling employees across multiple sectors including finance, healthcare, and legal services. The attack technique resembles previous router-based campaigns linked to the APT28 group. Researchers observed malicious domains and attempted abuse of WPAD for traffic interception.
bleeping-computer ·1mo ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a zero-day vulnerability (CVE-2025-66376) in Zimbra's webmail client to conduct cyber espionage against Western government and commercial organizations. The vulnerability allowed attackers to steal emails, passwords, and 2FA codes through a zero-click exploit triggered by viewing a malicious email. The campaign, active since at least July 2025, used HTML smuggling and DNS-based exfiltration, targeting sectors including government, defense, and finance across NATO, Ukraine, CIS, and Africa.
hacker-news ·1mo ago
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the US and allied nations have issued a joint advisory warning of Russian state-sponsored hackers, attributed to FSB Center 16, targeting critical infrastructure by exploiting misconfigured routers and known vulnerabilities. The threat actor scans for devices using default SNMP credentials and exploits CVE-2018-0171 in Cisco Smart Install to gain control of network devices. Sectors at risk include energy, healthcare, defense, and government services. The advisory emphasizes mitigation steps such as disabling vulnerable features, upgrading to SNMPv3, and blocking unauthorized protocols at firewalls.
bleeping-computer ·1mo ago
Zimbra urges customers to patch critical web client XSS flaw
Zimbra has urged customers to patch a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client, which could allow attackers to execute malicious code via specially crafted emails. The flaw affects Zimbra Collaboration Suite users and could lead to theft of session data, account settings, or mailbox contents. Although no CVE has been assigned yet, the vulnerability was reported by Google's Threat Analysis Group and is suspected to be exploited by state-backed actors, particularly Russian-linked groups.
bleeping-computer ·1mo ago