APT28__2025__CERTFR-2025-CTI-007.pdf
ID: 96f38e58-13d0-40d0-a061-1dea17f40235
STIX ID: report--96f38e58-13d0-40d0-a061-1dea17f40235
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ANSSI (Apr 29, 2025) reports that the APT28 intrusion set has been actively targeting and compromising French entities since 2021 for espionage purposes; campaigns use phishing, exploitation (including CVE-2023-23397), brute-force, and compromised edge devices, leveraging low-cost outsourced infrastructure and malware (e.g., HeadLace, OceanMap stealer) to exfiltrate credentials and emails while primarily affecting government, DTIB, aerospace, research and financial sectors.
