logo

AR-17-20045 Enhanced Analysis of GRIZZLY STEPPE Activity

ID: df026b1f-ae9a-46c2-8568-13d41cf2f43a

STIX ID: report--df026b1f-ae9a-46c2-8568-13d41cf2f43a

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2017-02-10

Last Modified Date: 2017-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This DHS NCCIC/US‑CERT analytical report details GRIZZLY STEPPE activity (attributed to APT28/APT29), describing reconnaissance, delivery (spear‑phishing, watering holes), exploitation (multiple CVEs), installation (webshells, RATs), C2 mechanisms (compromised domains, TOR), and actions on objectives (credential and certificate theft, data exfiltration). The report includes extensive technical artefacts — file hashes, YARA rules, Snort alerts, domain/IP IOCs, sample network traffic, and mitigation/detection guidance for defenders.