AR-17-20045 Enhanced Analysis of GRIZZLY STEPPE Activity
ID: df026b1f-ae9a-46c2-8568-13d41cf2f43a
STIX ID: report--df026b1f-ae9a-46c2-8568-13d41cf2f43a
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2017-02-10
Last Modified Date: 2017-02-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This DHS NCCIC/US‑CERT analytical report details GRIZZLY STEPPE activity (attributed to APT28/APT29), describing reconnaissance, delivery (spear‑phishing, watering holes), exploitation (multiple CVEs), installation (webshells, RATs), C2 mechanisms (compromised domains, TOR), and actions on objectives (credential and certificate theft, data exfiltration). The report includes extensive technical artefacts — file hashes, YARA rules, Snort alerts, domain/IP IOCs, sample network traffic, and mitigation/detection guidance for defenders.
