created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
APT28
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0007 |
| Aliases | IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch |
| Attribution | Russia |
| Class | state |
| Active since | 2004 (per ATT&CK description) |
| ATT&CK entry created | 2017-05-31 |
| Techniques mapped | 122 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1001.001 |
Junk Data |
T1003 |
OS Credential Dumping |
T1003.001 |
LSASS Memory |
T1003.003 |
NTDS |
T1005 |
Data from Local System |
T1014 |
Rootkit |
T1021.002 |
SMB/Windows Admin Shares |
T1025 |
Data from Removable Media |
T1027.013 |
Encrypted/Encoded File |
T1030 |
Data Transfer Size Limits |
T1036 |
Masquerading |
T1036.005 |
Match Legitimate Resource Name or Location |
(First 12 of 122 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Apt29 — Russia-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0007 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.