APT28: A Window into Russia's Cyber Espionage Operations
ID: 8b22d51b-ccad-4543-854c-f301f6c70f58
STIX ID: report--8b22d51b-ccad-4543-854c-f301f6c70f58
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2014-10-27
Last Modified Date: 2014-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report profiles APT28, a long-running, highly capable espionage group assessed to be sponsored by the Russian government that has targeted Georgian and Eastern European government and military organizations, NATO and other security bodies, journalists, and defense exhibitions; the analysis details modular malware families (SOURFACE/CORESHELL downloader, EVILTOSS backdoor, CHOPSTICK modular implant, OLDBAIT credential stealer), spearphishing lures and domain impersonation tactics, observed indicators of compromise, and metadata (Russian language PE resources and compile times) used to support attribution.
