← Back to all threat actors

APT28

Also known as IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, BlueDelta
Tracked as G0007

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
RU
Sectors
government, defense, media-journalism
Status
Active

Threat intelligence assessment

At a glance

Facts

  • Russian state-sponsored hacking group attributed with moderate confidence to campaigns targeting European government and diplomatic organizations

Activity timeline

Facts

  • Targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026
  • Deployed HOOKEDGE backdoor via macro-enabled Microsoft Word documents with diplomatic-themed lures
  • Early versions impersonated Spanish government material before switching to social engineering approach

Attribution assessment

Facts

  • HOOKEDGE is assessed as a direct evolutionary successor to HEADLACE, previously used by APT28 since April 2023

Initial access and identity targets

Facts

  • Macro-enabled Microsoft Word documents bearing diplomatic-themed lures distributed to targets
  • Documents prompt users to click 'Enable Content' to display contents

Capabilities and evasion

Facts

  • HOOKEDGE is a lightweight Windows batch script backdoor that executes remote commands
  • Fetches arbitrary .cmd payloads from staging webhooks and executes them
  • Sends command output back to webhook URLs using HTML files
  • Launches Microsoft Edge in headless mode or hidden window to make HTTP requests
  • Deletes temporary files and terminates processes matching task identifiers after data transmission
  • Two-stage architecture with beaconing intervals as little as five minutes for high-value targets

Infrastructure patterns

Facts

  • Abuses webhook.site services for command-and-control, payload staging, and data exfiltration
  • Uses webhook.site free tier (maximum 100 requests per unique endpoint)
  • Embeds hidden image in lure documents referencing webhook.site URL to alert operators when document is opened
  • Separates initial-access infrastructure from active collection infrastructure using dedicated second-stage webhook endpoints

Communication and pressure channels

Facts

  • Communicates via webhook.site services to blend malicious activity with regular network traffic
  • First-stage implant operates on 30-minute beaconing interval
  • Second-stage payload against high-value targets uses beaconing intervals as little as five minutes

Observed targeting

Facts

  • Focuses on European government and diplomatic targets
  • Uses intelligence from first-stage implant to identify higher-value victims for escalated collection

Named victims

Organizations

  • Romanian government and diplomatic organizations
  • Spanish government and diplomatic organizations
  • Turkish government and diplomatic organizations

Defender guidance

Facts

  • Prioritize blocking macro execution from internet-originated documents
  • Implement detection coverage for scheduled task abuse
  • Implement detection coverage for headless Microsoft Edge execution
  • Implement detection coverage for outbound connections to webhook services

Reported detail

Facts

  • APT28 deployed HOOKEDGE, a lightweight Windows batch backdoor, in campaigns targeting European government and diplomatic organizations from September 2025 to April 2026 through macro-enabled Word documents.
  • HOOKEDGE is assessed as a direct evolutionary successor to the HEADLACE backdoor, sharing significant code overlap and relying on webhook.site for command-and-control and data exfiltration.
  • The backdoor uses a two-stage architecture with differentiated beaconing intervals, separating initial-access infrastructure from active collection infrastructure to manage webhook.site's 100-request-per-endpoint limitation.
  • APT28 continuously refined HOOKEDGE's tradecraft between deployments, including removing document-open canaries and adapting to reduced API limits, suggesting deliberate operational adaptation.
  • The group demonstrates focus on lightweight, easily adaptable tooling refined through iterative operational experience rather than introducing entirely new capabilities.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator3 indicators cataloged

Types: domain, tool.

Cataloged
IdentityAlias: Fancy Bear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Forest Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BlueDelta

Reviewed identity mapping approved on this date.

First observed
CVECVE-2026-58231 linked to this actor

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cataloged
IdentityAlias: IRON TWILIGHT

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: SNAKEMACKEREL

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Swallowtail

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Group 74

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Sednit

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Sofacy

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Pawn Storm

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Fancy Bear

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: STRONTIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Tsar Team

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Threat Group-4127

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TG-4127

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Forest Blizzard

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: FROZENLAKE

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: GruesomeLarch

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0007

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2023-23397 linked to this actor
Cataloged
CVECVE-2024-21762 linked to this actor
Last observed
CampaignAPT28 Nearest Neighbor Campaign

APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living…

First observed
CVECVE-2022-38028 linked to this actor

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT28Canonical Name
FROZENLAKEAlias
Fancy BearAlias
Forest BlizzardAlias
Group 74Alias
GruesomeLarchAlias
IRON TWILIGHTAlias
Pawn StormAlias
SNAKEMACKERELAlias
STRONTIUMAlias
SednitAlias
SofacyAlias
SwallowtailAlias
TG-4127Alias
Threat Group-4127Alias
Tsar TeamAlias
BlueDeltaAlias
G0007Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...