logo

APT28__2025__CERTFR-2025-CTI-007.pdf

ID: 96f38e58-13d0-40d0-a061-1dea17f40235

STIX ID: report--96f38e58-13d0-40d0-a061-1dea17f40235

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ANSSI (Apr 29, 2025) reports that the APT28 intrusion set has been actively targeting and compromising French entities since 2021 for espionage purposes; campaigns use phishing, exploitation (including CVE-2023-23397), brute-force, and compromised edge devices, leveraging low-cost outsourced infrastructure and malware (e.g., HeadLace, OceanMap stealer) to exfiltrate credentials and emails while primarily affecting government, DTIB, aerospace, research and financial sectors.