Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G0007 (APT28).
- Linked to 2 primary court prosecution records.
- Identified 3 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1566.002 Spearphishing Link | 1 incidents |
| T1059.001 PowerShell | 1 incidents |
| T1583.001 Domains | 1 incidents |
| T1071.004 DNS Tunneling | 1 incidents |
| T1546.003 Windows Management Instrumentation Event Subscription | 1 incidents |
| T1566.001 Spearphishing Attachment | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)
Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.
U.S. & International Action: Dmitry Badin (German Bundestag Hack)
Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.
Targeted Defensive Hardening for APT28
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.