Sofacy, APT 28, Fancy Bear, Sednit

Description

APT 28 is a threat group that has been attributed to Russia’s Main Intelligence Directorate of the Russian General Staff by a July 2018 U.S. Department of Justice indictment. This group reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. APT 28 has been active since at least January 2007.

(FireEye) APT28 likely seeks to collect intelligence about Georgia’s security and political dynamics by targeting officials working for the Ministry of Internal Affairs and the Ministry of Defense.

APT28 has demonstrated interest in Eastern European governments and security organizations. These victims would provide the Russian government with an ability to predict policymaker intentions and gauge its ability to influence public opinion.

APT28 appeared to target individuals affiliated with European security organizations and global multilateral institutions. The Russian government has long cited European security organizations like NATO and the OSCE as existential threats, particularly during periods of increased tension in Europe.

Sofacy may be related to Hades, but it could be a false flag as well.

Names

NameName-Giver
SofacyKaspersky
APT 28Mandiant
Fancy BearCrowdStrike
SednitESET
Group 74Talos
TG-4127SecureWorks
Pawn StormTrend Micro
Tsar TeamiSight
StrontiumMicrosoft
SwallowtailSymantec
SIG40NSA
SnakemackereliDefense
Iron TwilightSecureWorks
ATK 5Thales
T-APT-12Tencent
ITG05IBM
TAG-0700Recorded Future
UAC-0028CERT-UA
FROZENLAKEGoogle
Grey-Cloud?
Grizzly SteppeUS Government
Forest BlizzardMicrosoft
GruesomeLarchVolexity
BlueDeltaRecorded Future
TA422Proofpoint
Fighting UrsaPalo Alto
Blue AthenaPWC
UAC-0063CERT-UA
TAG-110Recorded Future

Country

State-sponsored, two GRU units known as Unit 26165 and Unit 74455

Motivation

  • Information theft and espionage

First Seen

2004

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

e6037735-ed1b-4ae3-a45b-45d66e2c80f1

Last Card Change

2025-06-28