Home
Glossary
APT28
Table of contents
5 min
H2 title on one or more lines.
Share
Updated on
June 22, 2026

APT28 (also known as Fancy Bear, Sofacy or Sednit)

APT28 (also known as Fancy Bear) is a Russian state-sponsored threat actor active since at least 2004. Attributed to the GRU (Russian Military Intelligence), the group specializes in cyber espionage, targeting government, military, and security organizations globally to gather strategic intelligence and influence political outcomes.

Key takeaways

  • Origin: Russian Federation, specifically linked to the GRU (Units 26165 and 74455).
  • Motivations: Strategic intelligence gathering, political subversion, and disinformation.
  • Core tactics: Advanced spear-phishing, OAuth token theft, and zero-day exploitation.
  • Notable targets: US DNC (2016), WADA, NATO, and European government entities.

The origins and affiliations of APT28

APT28 is not a rogue group operating independently. It is a structured military unit. Intelligence agencies worldwide, including the FBI and the UK's NCSC, have formally attributed APT28 to the Main Intelligence Directorate (GRU) of the Russian General Staff. Specifically, the group is associated with Unit 26165 (specializing in cryptography and signals intelligence) and Unit 74455 (involved in information operations).

Unlike cybercriminal groups motivated by financial gain, APT28 operates in direct support of Russian geopolitical interests. Active for over two decades, the group's longevity reflects consistent state funding, training, and strategic direction.

Common aliases

  • Fancy Bear
  • Pawn Storm
  • Strontium
  • Sofacy
  • Sednit

Targeting profile: who does APT28 attack?

APT28's target selection directly reflects Russia's foreign policy priorities.

Government and diplomatic entities

Ministries of Foreign Affairs and embassies in NATO member states and Eastern Europe, particularly Ukraine, are primary targets for intelligence collection.

Military organizations

Defense contractors and military commands are targeted to gain insights into troop movements, weapon systems, and strategic planning.

Political organizations and elections

The 2016 Democratic National Committee (DNC) breach remains APT28's most prominent operation. The goal was to influence a foreign election through a "hack-and-leak" campaign, with stolen emails released via DCLeaks and Guccifer 2.0.

Critical infrastructure and media

By compromising media outlets and infrastructure providers, APT28 can support large-scale disinformation campaigns designed to destabilize societies.

The APT28 toolkit: malware and infrastructure

APT28 maintains a diverse, evolving arsenal of custom-built malware designed for stealth, persistence, and data theft.

Primary malware families

  • X-Agent (CHOPSTICK): A modular trojan used for data exfiltration and keystroke logging across multiple platforms (Windows, Linux, macOS, iOS).
  • X-Tunnel: A tool that creates encrypted tunnels to exfiltrate data while bypassing network security controls.
  • SedUploader: A first-stage reconnaissance tool used to identify high-value targets.
  • Zebrocy: A high-volume downloader deployed in extensive phishing campaigns.
  • Zekapab: A beaconing tool used to establish long-term persistence within a network.

Exploitation tactics

APT28 is known for rapid weaponization of zero-day vulnerabilities. The group frequently targets software like Microsoft Office and Windows kernel components to escalate privileges and move laterally through a network.

Tactics, techniques, and procedures (TTPs)

Mapped against the MITRE ATT&CK framework, APT28's TTPs are characterized by high operational security and adaptability.

Initial access: beyond simple phishing

Spear-phishing remains a staple, but APT28 has developed more advanced intrusion methods:

  • OAuth token theft: Instead of stealing passwords directly, they trick users into authorizing a malicious application via Google or Microsoft OAuth, granting persistent access to email without ever needing credentials.
  • Brute force and password spraying: Targeting VPNs and webmail portals with large-scale credential guessing.

Credential access and lateral movement

Once inside, APT28 uses tools like Mimikatz to extract plaintext passwords or hashes. The group then uses PowerShell and Windows Management Instrumentation (WMI) to move through the network, often relying on legitimate administrative tools to avoid detection, a technique known as "living off the land" (LotL).

APT28 vs. APT29 (Cozy Bear)

Both are Russian state-sponsored actors, but their methods and objectives differ significantly.

APT28 APT29
Agency GRU (Military Intelligence) SVR (Foreign Intelligence)
Style Aggressive, operationally loud Stealthy, patient, long-term
Objective Disruption, influence operations, military intelligence Deep-cover espionage, political intelligence
Notable operation 2016 US DNC breach SolarWinds supply chain attack

Notable APT28 operations

Operation Grizzly Steppe

The US government's designation for the collective Russian operations targeting the 2016 elections. APT28 was identified as responsible for the DNC intrusion and the subsequent release of stolen emails via DCLeaks and Guccifer 2.0.

The WADA breach

In 2016, APT28 compromised the World Anti-Doping Agency (WADA) in response to the ban on Russian athletes. The group leaked confidential medical records to discredit the agency and international sports bodies.

Targeting NATO and European parliaments

APT28 has conducted sustained campaigns against NATO headquarters and various European parliaments, using stolen documents to generate discord within the alliance.

Defending against APT28

Because APT28 targets people as much as systems, defense needs to work at multiple levels:

  • Enforce phishing-resistant MFA: Move away from SMS and push notifications toward hardware security keys (FIDO2) to prevent OAuth abuse and credential theft.
  • Behavioral monitoring (EDR/XDR): Watch for unusual PowerShell execution or credential dumping activity, both common indicators of lateral movement.
  • Patch management: Prioritize critical vulnerabilities in perimeter devices (firewalls, VPNs) and email gateways.
  • Threat intelligence integration: Use CTI-led platforms to block known APT28 command-and-control (C2) infrastructure before an attack begins.

How Sekoia helps track and neutralize APT28

At Sekoia, we track APT28 through our Sekoia Intelligence platform. We provide customers with high-fidelity Indicators of Compromise (IoCs) and context-rich reports on APT28 infrastructure. By integrating our Cyber Threat Intelligence (CTI) directly into the Sekoia SOC platform (XDR), security teams can automatically detect and block Fancy Bear's latest tactics in real time.

Frequently asked questions

Who is behind APT28?

The group is attributed to the Russian GRU (Military Intelligence), specifically Units 26165 and 74455.

Is APT28 the same as APT29?

No. Both are Russian state-sponsored actors, but APT28 is run by the military (GRU) and operates more aggressively, while APT29 is run by the SVR (Foreign Intelligence Service) and focuses on long-term, covert espionage.

What malware does APT28 use?

Their core tools include X-Agent, X-Tunnel, and the Zebrocy downloader, among others.

How can I detect APT28 activity?

Detection requires monitoring for phishing attempts (particularly OAuth abuse), credential access tools like Mimikatz, and suspicious C2 traffic, ideally cross-referenced with up-to-date threat intelligence feeds.