Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

APT28

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004.

Attribute Detail
ATT&CK ID G0007
Aliases IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch
Attribution Russia
Class state
Active since 2004 (per ATT&CK description)
ATT&CK entry created 2017-05-31
Techniques mapped 122

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1001.001 Junk Data
T1003 OS Credential Dumping
T1003.001 LSASS Memory
T1003.003 NTDS
T1005 Data from Local System
T1014 Rootkit
T1021.002 SMB/Windows Admin Shares
T1025 Data from Removable Media
T1027.013 Encrypted/Encoded File
T1030 Data Transfer Size Limits
T1036 Masquerading
T1036.005 Match Legitimate Resource Name or Location

(First 12 of 122 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Apt29 — Russia-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0007 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.