CXO Corner

The Russian Bear Unleashed: The Cyber Threat of APT28

The Russian Bear, a symbol deeply ingrained in Russian culture, is often associated with the Eurasian brown bear. This majestic creature, known for its immense strength and solitary nature, embodies the vast and untamed landscapes of Russia. From the dense forests of Siberia to the remote wilderness of Kamchatka, the Russian Bear roams freely, captivating imaginations and evoking a sense of awe and respect.

APT28, also known as Fancy Bear, amongst other aliases, does not evoke the same sense of awe and respect, well not from a Cyber Defenders perspective. AP28 is a highly sophisticated cyber espionage group assessed to be linked to the Russian General Staff Main Intelligence Directorate (GRU) 85th special Service Centre (GTsSS) Military Intelligence Unit.

Estonian and British intelligence services have also associated APT28 with Russian military intelligence (GRU). The United States believes that GRU units 26165 and 74455 form part of this threat actor. APT28 has been active since at least 2004.

Targets and Objectives

APT28 primarily targets:

The group’s objectives include:

Tactics, Techniques and Procedures (TTPs)

APT28 is known for its sophisticated and constantly evolving TTPs, which include:

Notable Malware and Tools

APT28 uses a range of custom-developed and publicly available malware and tools, including:

Notable Attacks

APT28 has been linked to several high-profile cyberattacks, including:

Mitigating the Threat

Organisations can take steps to mitigate the threat posed by APT28 and other advanced persistent threats:

Exit mobile version