logo

APT28 (Sofacy)

Technical threat-intel reports on the Russia-linked APT28 (aka Sofacy/Fancy Bear/Sednit) group detailing espionage campaigns, malware families, exploited CVEs, TTPs, and IOCs.

List of reports related to this topic

Title
APT28__2014__apt28.pdf
APT28__2014__tactical-intelligence-bulletin---sofacy-phishing-.pdf
APT28__2015__Bitdefender_In-depth_analysis_of_APT28_The_Political_Cyber-Espionage.pdf
APT28__2015__cto-tib-20150420-01a.pdf
APT28__2015__FSOFACY.pdf
APT28__2015__R9b_FSOFACY_0.pdf
APT28__2016__eset-sednit-part-2.pdf
APT28__2016__eset-sednit-part3.pdf
APT28__2017__APT28-Center-of-Storm-2017.pdf
APT28__2017__A_Slice_of_2017_Sofacy_Activity_-_Securelist.pdf
APT28__2017__New_Xagent_Mac_Malware_Linked_with_the_APT28_Bitdefender_Labs.pdf
APT28__2018__20180713_CSE_APT28_X-Agent_Op-Roman_Holiday-Report_v6_1.pdf
APT28__2018__4OctoberIOC-APT28-malware-advisory.pdf
APT28__2018__Sofacy_Attacks_Multiple_Government_Entities.pdf
APT28__2019__A_journey_to_Zebrocy_land.pdf
APT28__2023__APT28_CERTFR_2023_EN.pdf
APT28__2023__CERTFR-2023-CTI-009.pdf
APT28__2025__CERTFR-2025-CTI-007.pdf
APT28: A Window into Russia's Cyber Espionage Operations
APT28, the long hand of Russian interests Eng 2.0
APT31 Intrusion set campaign: description, countermeasures and code
Campagnes d'attaques du mode opératoire APT28 depuis 2021
cyberespionage-gamaredon-way.pdf
Sofacy APT hits high profile targets with updated toolset - Securelist
Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog
Targeting and compromise of french entities using the APT28 intrusion set
[tr1adx]: Intel

1–27 of 27