THREAT-WATCH logo

THREAT‑WATCH

Threat Actors

APT28

Fancy Bear, Sofacy, Sednit

ActiveState-sponsored (Russia)

A cyberespionage group widely attributed by Western governments to Russia's military intelligence agency (GRU), active since at least the mid-2000s.

APT28 focuses on political and military intelligence gathering, typically through spear-phishing and credential harvesting against government, military, and political targets. It was publicly attributed by US intelligence agencies to the compromise of the Democratic National Committee ahead of the 2016 US election, among many other documented operations across Europe and the Americas. It remains one of the most closely tracked state-sponsored groups by Western security agencies and continues active operations.

Target Sectors

Government, military, defense contractors, and political organizations, with a strong focus on Europe and NATO member states.

24/7 SOC Monitoring & MDR