Also known as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, BlueDelta
Tracked asG0007
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
Russian state-sponsored hacking group attributed with moderate confidence to campaigns targeting European government and diplomatic organizations
Activity timeline
Facts
Targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026
Deployed HOOKEDGE backdoor via macro-enabled Microsoft Word documents with diplomatic-themed lures
Early versions impersonated Spanish government material before switching to social engineering approach
Attribution assessment
Facts
HOOKEDGE is assessed as a direct evolutionary successor to HEADLACE, previously used by APT28 since April 2023
Initial access and identity targets
Facts
Macro-enabled Microsoft Word documents bearing diplomatic-themed lures distributed to targets
Documents prompt users to click 'Enable Content' to display contents
Capabilities and evasion
Facts
HOOKEDGE is a lightweight Windows batch script backdoor that executes remote commands
Fetches arbitrary .cmd payloads from staging webhooks and executes them
Sends command output back to webhook URLs using HTML files
Launches Microsoft Edge in headless mode or hidden window to make HTTP requests
Deletes temporary files and terminates processes matching task identifiers after data transmission
Two-stage architecture with beaconing intervals as little as five minutes for high-value targets
Infrastructure patterns
Facts
Abuses webhook.site services for command-and-control, payload staging, and data exfiltration
Uses webhook.site free tier (maximum 100 requests per unique endpoint)
Embeds hidden image in lure documents referencing webhook.site URL to alert operators when document is opened
Separates initial-access infrastructure from active collection infrastructure using dedicated second-stage webhook endpoints
Communication and pressure channels
Facts
Communicates via webhook.site services to blend malicious activity with regular network traffic
First-stage implant operates on 30-minute beaconing interval
Second-stage payload against high-value targets uses beaconing intervals as little as five minutes
Observed targeting
Facts
Focuses on European government and diplomatic targets
Uses intelligence from first-stage implant to identify higher-value victims for escalated collection
Named victims
Organizations
Romanian government and diplomatic organizations
Spanish government and diplomatic organizations
Turkish government and diplomatic organizations
Defender guidance
Facts
Prioritize blocking macro execution from internet-originated documents
Implement detection coverage for scheduled task abuse
Implement detection coverage for headless Microsoft Edge execution
Implement detection coverage for outbound connections to webhook services
Reported detail
Facts
APT28 deployed HOOKEDGE, a lightweight Windows batch backdoor, in campaigns targeting European government and diplomatic organizations from September 2025 to April 2026 through macro-enabled Word documents.
HOOKEDGE is assessed as a direct evolutionary successor to the HEADLACE backdoor, sharing significant code overlap and relying on webhook.site for command-and-control and data exfiltration.
The backdoor uses a two-stage architecture with differentiated beaconing intervals, separating initial-access infrastructure from active collection infrastructure to manage webhook.site's 100-request-per-endpoint limitation.
APT28 continuously refined HOOKEDGE's tradecraft between deployments, including removing document-open canaries and adapting to reduced API limits, suggesting deliberate operational adaptation.
The group demonstrates focus on lightweight, easily adaptable tooling refined through iterative operational experience rather than introducing entirely new capabilities.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator3 indicators cataloged
Types: domain, tool.
Cataloged
IdentityAlias: Fancy Bear
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Forest Blizzard
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: BlueDelta
Reviewed identity mapping approved on this date.
First observed
CVECVE-2026-58231 linked to this actor
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cataloged
IdentityAlias: IRON TWILIGHT
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: SNAKEMACKEREL
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Swallowtail
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Group 74
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Sednit
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Sofacy
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Pawn Storm
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Fancy Bear
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: STRONTIUM
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Tsar Team
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Threat Group-4127
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: TG-4127
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Forest Blizzard
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: FROZENLAKE
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: GruesomeLarch
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: G0007
Reviewed identity mapping approved on this date.
Cataloged
CVECVE-2023-23397 linked to this actor
Cataloged
CVECVE-2024-21762 linked to this actor
Last observed
CampaignAPT28 Nearest Neighbor Campaign
APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living…
First observed
CVECVE-2022-38028 linked to this actor
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
APT28Canonical Name
FROZENLAKEAlias
Fancy BearAlias
Forest BlizzardAlias
Group 74Alias
GruesomeLarchAlias
IRON TWILIGHTAlias
Pawn StormAlias
SNAKEMACKERELAlias
STRONTIUMAlias
SednitAlias
SofacyAlias
SwallowtailAlias
TG-4127Alias
Threat Group-4127Alias
Tsar TeamAlias
BlueDeltaAlias
G0007Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...