logo

Threat Group-4127 Targets Hillary Clinton Presidential Campaign

ID: ceb154de-ea5f-4aa4-924e-aee193019653

STIX ID: report--ceb154de-ea5f-4aa4-924e-aee193019653

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2016-11-04

Last Modified Date: 2016-11-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SecureWorks CTU observed Threat Group-4127 (aka APT28/Sofacy) running a spearphishing campaign (Oct 2015–May 2016) that used Bitly-shortened URLs to redirect victims to spoofed Google Account login pages to harvest Gmail credentials from targets including Hillary for America, the DNC, and related personnel; the report documents scope (e.g., 8,909 Bitly links targeting 3,907 Gmail accounts and 213 links targeting 108 hillaryclinton.com addresses), observed click counts, suspected Russian government intelligence objectives, and recommended mitigations.