Threat Group-4127 Targets Hillary Clinton Presidential Campaign
ID: 76e4e5fb-c163-44c1-be37-85ac73324008
STIX ID: report--76e4e5fb-c163-44c1-be37-85ac73324008
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-06-17
Last Modified Date: 2016-06-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SecureWorks CTU reports that Threat Group-4127 (associated with APT28/Sofacy) ran a targeted spearphishing campaign from mid-2015 through May 2016 using Bitly-shortened links that redirected to spoofed Google login pages to harvest credentials; the campaign targeted hillaryclinton.com, dnc.org, and affiliated personal Gmail accounts (including senior campaign staff), produced measurable click activity, and allowed potential access to email and Google Drive. The report attributes the group to the Russian Federation with moderate confidence, outlines the techniques and scope, notes operational implications (credential access, persistent sessions, potential for follow-on attacks), and recommends user education and caution with shortened URLs and spoofed login pages.
