logo

Targeting and compromise of french entities using the APT28 intrusion set

ID: 10a658ca-de2a-4c31-ad15-8e19e89754be

STIX ID: report--10a658ca-de2a-4c31-ad15-8e19e89754be

Threat Score

90/100

Uploaded: 2026-07-29

Published Date: 2026-07-29

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI warns that the APT28 intrusion set has repeatedly targeted and compromised French governmental, defence, research, and private-sector entities since 2021, using phishing, exploitation of CVE-2023-23397, brute-force and compromised edge devices to deploy backdoors (e.g., HeadLace) and stealers (e.g., OceanMap), often leveraging free hosting and temporary infrastructure; the bulletin details infection chains, victimology, notable campaigns, and references for mitigation.