APT28__2016__eset-sednit-part1.pdf
ID: 165aebc0-37ec-479e-ac64-7fcb1230c078
STIX ID: report--165aebc0-37ec-479e-ac64-7fcb1230c078
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-10-14
Last Modified Date: 2016-10-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
## Executive summary
This ESET whitepaper (Part 1) analyzes the Sednit (APT28/Fancy Bear) group's targeted espionage operations from 2014–2016, documenting large-scale spearphishing against ~1,000+ high‑profile targets, use of a bespoke exploit kit (Sedkit) delivering multiple 0‑day and public exploits, the Seduploader reconnaissance/downloader (with sophisticated persistence and network-evasion techniques), and extensive IoCs (domains, hashes, file names, registry keys) to aid detection and response.
