← Back to all campaigns
ActiveMITRE ATT&CK

APT28 Nearest Neighbor Campaign

APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.

First observedFeb 1, 2022
Last observedNov 1, 2024
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 20...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

APT28 attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

APT28 Nearest Neighbor Campaign last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

APT28 Nearest Neighbor Campaign first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Malware and tools 29

  • ADVSTORESHELLMalware | APT28
  • CHOPSTICKMalware | APT28
  • CORESHELLMalware | APT28
  • CannonMalware | APT28
  • DealersChoiceMalware | APT28
  • DowndelphMalware | APT28
  • DrovorubMalware | APT28
  • FysbisMalware | APT28
  • HIDEDRVMalware | APT28
  • JHUHUGITMalware | APT28
  • KomplexMalware | APT28
  • LAMEHUGMalware | APT28

Indicators 3

  • HEADLACETOOL | APT28
  • HOOKEDGETOOL | APT28
  • webhook.siteDOMAIN | APT28
Sources

Evidence behind this page

Open the original material before making an attribution or response decision.