MITRE ATT&CK G0007
Aliases: Fancy Bear, Sofacy, Sednit, STRONTIUM, Unit 26165
Official Attribution Source: U.S. Department of Justice Indictment (D.D.C.)

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
2
Prosecution matters
Defendants
3
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0007 (APT28).
  • Linked to 2 primary court prosecution records.
  • Identified 3 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to APT28 Technique frequencies extracted from verified indictments for APT28. T1566.002 Spearphishing Link 1 incidents T1059.001 PowerShell 1 incidents T1583.001 Domains 1 incidents T1071.004 DNS Tunneling 1 incidents T1546.003 Windows Management Instrumentation Event Subscription 1 incidents T1566.001 Spearphishing Attachment 1 incidents
Technique frequencies extracted from verified indictments for APT28.
ATT&CK Techniques Mapped to APT28
Technique Frequency
T1566.002 Spearphishing Link 1 incidents
T1059.001 PowerShell 1 incidents
T1583.001 Domains 1 incidents
T1071.004 DNS Tunneling 1 incidents
T1546.003 Windows Management Instrumentation Event Subscription 1 incidents
T1566.001 Spearphishing Attachment 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2018-07-13

U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)

Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.

5 techniques View case →
fugitive 2020-05-05

U.S. & International Action: Dmitry Badin (German Bundestag Hack)

Russian GRU military officer charged with the 2015 cyber intrusion into the German Federal Parliament (Bundestag), which compromised parliamentary IT infrastructure and exfiltrated thousands of emails from Chancellor Angela Merkel's office.

1 techniques View case →