APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.16
group
APT28 G0007
- Created
- 31 May 2017
- Last modified
- 31 July 2026
- Aliases
- APT28 · IRON TWILIGHT · SNAKEMACKEREL · Swallowtail · Group 74 · Sednit · Sofacy · Pawn Storm · Fancy Bear · STRONTIUM · Tsar Team · Threat Group-4127 · TG-4127 · Forest Blizzard · FROZENLAKE · GruesomeLarch
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2] This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13]
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[14] In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[15] Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0007
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.171819
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.2021 They have also dumped the LSASS process memory using the MiniDump function.22
During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: reg save hklm\sam, reg save hklm\system, and reg save hklm\security.23
APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.24
During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via vssadmin.25
APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.26272829
Standing G0007
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
99th percentile · 99% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
98th percentile · 98% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
17th percentile · 83% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0007
2011 distinct rules cover the 93 techniques recorded for this group. The 2330 technique-to-rule mappings resolve to 2011 distinct rules, because one rule can cover several techniques. 1327 Sigma · 684 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org