APT Russia (GRU Unit 26165) Active since 2004

APT28

Military intelligence. Election interference, Olympic targeting, NotPetya.

Scroll

APT28 is a Russian military intelligence cyber unit operating under GRU Unit 26165 (85th Main Special Service Center). Active since at least 2004, the group is responsible for some of the most consequential cyber operations in history including the 2016 US Democratic National Committee breach, Olympic anti-doping agency attacks, and the NotPetya destructive campaign.

AttributeDetail
NamesAPT28 / Fancy Bear / Forest Blizzard
AttributionRussia (GRU Unit 26165)
Active Since2004
Primary FocusMilitary intelligence. Election interference, Olympic targeting, NotPetya.

Overview

APT28 is a Russian military intelligence cyber unit operating under GRU Unit 26165 (85th Main Special Service Center). Active since at least 2004, the group is responsible for some of the most consequential cyber operations in history including the 2016 US Democratic National Committee breach, Olympic anti-doping agency attacks, and the NotPetya destructive campaign.

Attribution

APT28 / Fancy Bear / Forest Blizzard is attributed to Russia (GRU Unit 26165), active since at least 2004. Military intelligence. Election interference, Olympic targeting, NotPetya.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1566PhishingHigh
T1059Command and Scripting InterpreterHigh
T1071Application Layer ProtocolHigh
T1027Obfuscated Files or InformationHigh
T1190Exploit Public-Facing ApplicationHigh
T1078Valid AccountsHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for APT28 activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting APT28 TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875