logo

APT28__2017__Russian_Cyber_Operations_On_Steroids.pdf

ID: ea269635-ebd2-4f65-849f-faf2973d2928

STIX ID: report--ea269635-ebd2-4f65-849f-faf2973d2928

Threat Score

82/100

Uploaded: 2026-08-07

Published Date: 2017-11-03

Last Modified Date: 2017-11-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect research links credential-harvesting phishing domains (wada-awa.org, wada-arna.org, tas-cass.org) and associated infrastructure (81.95.5.166, 149.154.157.171) to tactics, techniques, and procedures used by the Russian APT FANCY BEAR (APT28). The report documents WHOIS/registrant evidence ([email protected], [email protected]), passive DNS and name-server patterns (ITitch, Domains4bitcoins), the compromise of WADA/CAS accounts (including Yuliya Stepanova), and considers timing and motive tied to WADA recommendations to ban Russian athletes; it also questions whether a claimed hacktivist group (Anonymous Poland) might be a platform used to obscure state involvement.