APT28__2017__Russian_Cyber_Operations_On_Steroids.pdf
ID: ea269635-ebd2-4f65-849f-faf2973d2928
STIX ID: report--ea269635-ebd2-4f65-849f-faf2973d2928
Threat Score
82/100
Uploaded: 2026-08-07
Published Date: 2017-11-03
Last Modified Date: 2017-11-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect research links credential-harvesting phishing domains (wada-awa.org, wada-arna.org, tas-cass.org) and associated infrastructure (81.95.5.166, 149.154.157.171) to tactics, techniques, and procedures used by the Russian APT FANCY BEAR (APT28). The report documents WHOIS/registrant evidence ([email protected], [email protected]), passive DNS and name-server patterns (ITitch, Domains4bitcoins), the compromise of WADA/CAS accounts (including Yuliya Stepanova), and considers timing and motive tied to WADA recommendations to ban Russian athletes; it also questions whether a claimed hacktivist group (Anonymous Poland) might be a platform used to obscure state involvement.
