logo

APT28: A Window into Russia's Cyber Espionage Operations

ID: 8b22d51b-ccad-4543-854c-f301f6c70f58

STIX ID: report--8b22d51b-ccad-4543-854c-f301f6c70f58

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2014-10-27

Last Modified Date: 2014-10-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's report profiles APT28, a long-running, highly capable espionage group assessed to be sponsored by the Russian government that has targeted Georgian and Eastern European government and military organizations, NATO and other security bodies, journalists, and defense exhibitions; the analysis details modular malware families (SOURFACE/CORESHELL downloader, EVILTOSS backdoor, CHOPSTICK modular implant, OLDBAIT credential stealer), spearphishing lures and domain impersonation tactics, observed indicators of compromise, and metadata (Russian language PE resources and compile times) used to support attribution.