news.mlab.sh
Threat intelligence
Threat actor

Sofacy

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
Targeted countries
Russia
TLP
WHITE

APT 28 is a threat group that has been attributed to Russia’s Main Intelligence Directorate of the Russian General Staff by a July 2018 U.S. Department of Justice indictment. This group reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. APT 28 has been active since at least January 2007. (FireEye) APT28 likely seeks to collect intelligence about Georgia’s security and political dynamics by targeting officials working for the Ministry of Internal Affairs and the Ministry of Defense. APT28 has demonstrated interest in Eastern European governments and security organizations. These victims would provide the Russian government with an ability to predict policymaker intentions and gauge its ability to influence public opinion. APT28 appeared to target individuals affiliated with European security organizations and global multilateral institutions. The Russian government has long cited European security organizations like NATO and the OSCE as existential threats, particularly during periods of increased tension in Europe. Sofacy may be related to Hades, but it could be a false flag as well.

Also known as

APT 28APT28ATK 5Blue AthenaBlueDeltaFancy BearFighting UrsaForest BlizzardFROZENLAKEG0007Grey-CloudGrizzly SteppeGroup 74GruesomeLarchIron TwilightITG05Pawn StormSednitSIG40SnakemackerelSofacyStrontiumSwallowtailT-APT-12TA422TAG-0700TAG-110TG-4127Threat Group-4127Tsar TeamUAC-0028UAC-0063

Vulnerabilities exploited

Tooling and malware

ADVSTORESHELLCannonCHOPSTICKCORESHELLDealersChoiceDowndelphDrovorubFysbisHIDEDRVJHUHUGITKomplexLAMEHUGLoJaxOLDBAITreGeorgUSBStealerXAgentOSXXTunnelZebrocycertutilcipher.exeForfilesKoadicMimikatzNetResponderTorWevtutilWinexe

MITRE ATT&CK techniques

T1005 Data from Local SystemT1025 Data from Removable MediaT1039 Data from Network Shared DriveT1113 Screen CaptureT1119 Automated CollectionT1213 Data from Information RepositoriesT1560 Archive Collected DataT1092 Communication Through Removable MediaT1105 Ingress Tool TransferT1003 OS Credential DumpingT1040 Network SniffingT1110 Brute ForceT1528 Steal Application Access TokenT1057 Process DiscoveryT1083 File and Directory DiscoveryT1120 Peripheral Device DiscoveryT1203 Exploitation for Client ExecutionT1030 Data Transfer Size LimitsT1567 Exfiltration Over Web ServiceT1498 Network Denial of ServiceT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1669 Wi-Fi NetworksT1091 Replication Through Removable MediaT1210 Exploitation of Remote ServicesT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1591 Gather Victim Org InformationT1596 Search Open Technical DatabasesT1598 Phishing for InformationT1014 RootkitT1036 MasqueradingT1078 Valid AccountsT1140 Deobfuscate/Decode Files or InformationT1211 Exploitation for StealthT1221 Template Injection

Coverage 13