{
  "id": "case-netyksho-apt28",
  "slug": "us-v-netyksho-apt28-dnc",
  "title": "U.S. v. Netyksho et al. (APT28 / GRU Unit 26165 DNC Hack)",
  "summary": "Twelve Russian GRU military intelligence officers charged with hacking into the Democratic National Committee and Hillary Clinton presidential campaign servers, exfiltrating emails, and orchestrating strategic leaks via DCLeaks and Guccifer 2.0.",
  "case_number": "1:18-cr-00215",
  "court": "U.S. District Court for the District of Columbia",
  "district": "D.D.C.",
  "country": "United States",
  "opened_at": "2018-07-13",
  "status": "fugitive",
  "victim_sector": "Political Organizations, Government",
  "victim_country": "United States",
  "loss_amount_usd": 10000000,
  "loss_amount_note": "Extensive campaign disruption and federal investigative expenditure.",
  "first_seen_at": "2016-03-15T00:00:00Z",
  "last_updated_at": "2026-09-02T10:00:00Z",
  "actor_slug": "apt28",
  "defendant_slugs": [
    "viktor-netyksho",
    "boris-antonov",
    "dmitriy-badin"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Conspirators sent spearphishing emails containing spoofed Google security warnings directing campaign staff to enter passwords on adversary domains.",
      "evidence_locator": "Indictment \u00b6 21, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Netyksho",
      "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1059.001",
      "evidence_excerpt": "Defendants used custom X-Agent malware and executed PowerShell scripts to automate file collection across internal exchange servers.",
      "evidence_locator": "Indictment \u00b6 33, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
      "technique_name": "PowerShell",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1583.001",
      "evidence_excerpt": "GRU officers registered misleading domain names such as dcleaks.com and actblues.com using cryptocurrency to stage leaks.",
      "evidence_locator": "Indictment \u00b6 28, Page 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Netyksho",
      "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
      "technique_name": "Domains",
      "tactic": "Resource Development"
    },
    {
      "technique_id": "T1071.004",
      "evidence_excerpt": "X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls.",
      "evidence_locator": "Indictment \u00b6 35, Page 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
      "technique_name": "DNS Tunneling",
      "tactic": "Command and Control"
    },
    {
      "technique_id": "T1546.003",
      "evidence_excerpt": "Adversaries created WMI event filters to ensure backdoor persistence whenever Windows booted.",
      "evidence_locator": "Indictment \u00b6 38, Page 17",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-presidential",
      "technique_name": "Windows Management Instrumentation Event Subscription",
      "tactic": "Persistence"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2018-07-13",
      "description": "Special Counsel Robert Mueller unseals 11-count indictment against 12 GRU military officers."
    }
  ]
}