Targeting and compromise of french entities using the APT28 intrusion set
ID: 10a658ca-de2a-4c31-ad15-8e19e89754be
STIX ID: report--10a658ca-de2a-4c31-ad15-8e19e89754be
Threat Score
90/100
Uploaded: 2026-07-29
Published Date: 2026-07-29
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI warns that the APT28 intrusion set has repeatedly targeted and compromised French governmental, defence, research, and private-sector entities since 2021, using phishing, exploitation of CVE-2023-23397, brute-force and compromised edge devices to deploy backdoors (e.g., HeadLace) and stealers (e.g., OceanMap), often leveraging free hosting and temporary infrastructure; the bulletin details infection chains, victimology, notable campaigns, and references for mitigation.
