← All actors Recent activity

APT28 G0007

SOFACY · KTA007 · SNAKEMACKEREL · STRONTIUM · TG-4127 · UAC-0001 · UAC-0028 · ZimReaper · apt-c-20 · apt28 · beardshell · fancy bear · gonepostal · group 74 · lamehug · pawn storm · sednit · ta422 · ta426 · threat troup-4127 · tsar team · zebrocy

Indicators
1,894
Source reports
301
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-07-24
20152026

Overview 1,894 indicators

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

domain1,431G0007-domain.txt
ipv4240G0007.json
url144G0007.json
url_path79G0007.json

Techniques 95 ATT&CK

Open in ATT&CK Navigator → or download the layer (95 techniques, layer 4.5)

Software 30

Principal sources 301 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

13 more in the relationship graph.

Timeline 1,894 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

Showing the 300 most recent of 1,894. Complete: G0007.json.

  1. 182 ipv4this year

    ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dn…

    103.140.186.148:53
    103.140.186.149:53
    103.140.186.155:53
    185.117.88.22:53
    185.117.88.28:53
    185.117.88.29:53
    185.117.88.30:53
    185.117.88.31:53
    185.117.88.50:53
    185.117.88.60:53
    185.117.88.61:53
    185.117.88.62:53
    185.117.89.32:53
    185.117.89.46:53
    185.117.89.47:53
    185.234.73.58:53
    185.234.73.61:53
    185.234.73.62:53
    185.237.166.224:53
    185.237.166.225:53
    185.237.166.226:53
    185.237.166.227:53
    185.237.166.228:53
    185.237.166.229:53
    185.237.166.230:53
    185.237.166.231:53
    185.237.166.232:53
    185.237.166.233:53
    185.237.166.234:53
    185.237.166.235:53
    185.237.166.236:53
    185.237.166.237:53
    185.237.166.238:53
    185.237.166.239:53
    185.237.166.240:53
    185.237.166.241:53
    185.237.166.242:53
    185.237.166.243:53
    185.237.166.244:53
    185.237.166.245:53
    185.237.166.246:53
    185.237.166.247:53
    185.237.166.248:53
    185.237.166.249:53
    185.237.166.55:53
    185.237.166.56:53
    185.237.166.57:53
    185.237.166.58:53
    185.237.166.59:53
    185.237.166.60:53
    185.237.166.61:53
    185.237.166.62:53
    185.237.166.63:53
    185.237.166.64:53
    185.237.166.65:53
    185.237.166.66:53
    185.237.166.67:53
    185.237.166.68:53
    185.237.166.69:53
    185.237.166.70:53
    185.237.166.71:53
    185.237.166.72:53
    185.237.166.73:53
    185.237.166.74:53
    185.237.166.75:53
    23.106.120.119:53
    37.221.64.101:53
    37.221.64.116:53
    37.221.64.131:53
    37.221.64.148:53
    37.221.64.149:53
    37.221.64.150:53
    37.221.64.151:53
    37.221.64.163:53
    37.221.64.173:53
    37.221.64.199:53
    37.221.64.208:53
    37.221.64.224:53
    37.221.64.254:53
    37.221.64.77:53
    37.221.64.78:53
    37.221.64.93:53
    5.226.137.151:53
    5.226.137.230:53
    5.226.137.231:53
    5.226.137.232:53
    5.226.137.234:53
    5.226.137.235:53
    5.226.137.242:53
    5.226.137.243:53
    5.226.137.244:53
    5.226.137.245:53
    64.120.31.100:53
    64.120.31.96:53
    64.120.31.97:53
    64.120.31.98:53
    64.120.31.99:53
    64.44.154.227:53
    64.44.154.237:53
    64.44.154.238:53
    64.44.154.239:53
    64.44.154.240:53
    77.83.197.37:53
    77.83.197.38:53
    77.83.197.39:53
    77.83.197.40:53
    77.83.197.41:53
    77.83.197.42:53
    77.83.197.43:53
    77.83.197.44:53
    77.83.197.45:53
    77.83.197.46:53
    77.83.197.47:53
    77.83.197.48:53
    77.83.197.49:53
    77.83.197.50:53
    77.83.197.51:53
    77.83.197.52:53
    77.83.197.53:53
    77.83.197.54:53
    77.83.197.55:53
    77.83.197.56:53
    77.83.197.57:53
    77.83.197.58:53
    77.83.197.59:53
    77.83.197.60:53
    77.83.198.39:53
    79.141.160.78:53
    79.141.161.66:53
    79.141.161.67:53
    79.141.161.68:53
    79.141.161.69:53
    79.141.161.70:53
    79.141.161.71:53
    79.141.161.72:53
    79.141.161.73:53
    79.141.161.74:53
    79.141.161.75:53
    79.141.161.76:53
    79.141.161.77:53
    79.141.161.78:53
    79.141.161.79:53
    79.141.161.80:53
    79.141.161.81:53
    79.141.161.82:53
    79.141.161.83:53
    79.141.161.84:53
    79.141.161.85:53
    79.141.173.103:53
    79.141.173.119:53
    79.141.173.120:53
    79.141.173.121:53
    79.141.173.122:53
    79.141.173.123:53
    79.141.173.200:53
    79.141.173.210:53
    79.141.173.211:53
    79.141.173.231:53
    79.141.173.232:53
    79.141.173.233:53
    79.141.173.246:53
    79.141.173.247:53
    79.141.173.248:53
    79.141.173.249:53
    79.141.173.250:53
    79.141.173.251:53
    79.141.173.252:53
    79.141.173.253:53
    79.141.173.254:53
    79.141.173.70:53
    79.141.173.96:53
    79.141.173.97:53
    79.141.173.98:53
    79.143.87.229:53
    79.143.87.232:53
    79.143.87.240:53
    79.143.87.243:53
    79.143.87.249:53
    88.80.148.49:53
    88.80.148.53:53
    89.150.40.43:53
    89.150.40.86:53

  2. 1 urlthis year

    x.com/smica83/status/2037477379530953027 · virustotal.com/gui/file/479fd5e5bd5566a0252acd4ec29c5a…

    webhook.site/c2dceeb0-d40d-41a2-8622-118fa974649c/

  3. 2 domainthis year

    trendmicro.com/en_us/research/26/c/pawn-storm-targets-… · documents.trendmicro.com/assets/txt/Pawn%20Storm%20Deploys%20PRI…

    910cf351-a05d-4f67-ab8e-6f62cfa8e26d.dnshook.site
    dbca10b5-63e0-42ec-ad10-de13be96dc42.dnshook.site

  4. 20 domainthis year

    x.com/TeamDreier/status/2035301205031719170 · seqrite.com/blog/operation-ghostmail-zimbra-xss-rus… · proofpoint.com/us/blog/threat-insight/ta488-targets-zi…

    analyticemailmeter.com
    emailanalytics.com.ua
    fraispei.com
    ftp.fraispei.com
    i.analyticemailmeter.com
    i.emailanalytics.com.ua
    i.mailnalysis.com
    i.zimbra-metadata.com
    i.zimbrasoft.com.ua
    i.zimbrastat.com
    i.zmailanalytics.com
    istc-cloud.com
    mailnalysis.com
    pro.fraispei.com
    synacorzimbra.nl
    test.fraispei.com
    zimbra-metadata.com
    zimbrasoft.com.ua
    zimbrastat.com
    zmailanalytics.com

  5. 2 domainthis year

    ctrlaltintel.com/threat%20research/FancyBear

    gov.vppdr.com
    vppdr.com

  6. 4 domain, 3 ipv4, 1 urlthis year

    cert.gov.ua/article/6281123 (# UAC-0001) · hunt.io/blog/operation-roundish-apt28-roundcube…

    domaina.zhblz.com
    domainns1.petdiary.net
    domainns2.petdiary.net
    domainpetdiary.net
    ipv4203.161.50.145:5000
    ipv4203.161.50.145:8080
    ipv4203.161.50.145:8889
    urlhttp://93.170.72.54

  7. 10 urlthis year

    x.com/LAB52io/status/2022281566513180933 · virustotal.com/gui/file/9097d9cf5e6659e869bf2edf766741…

    webhook.site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d/
    webhook.site/5744c020-a8d9-4755-abfb-cde6ccd450af/
    webhook.site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fba/
    webhook.site/62114596-33f5-47fb-9012-0223529e5a13/
    webhook.site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/
    webhook.site/a3f4e990-0b2a-4f6a-a02e-c573005de3ee/
    webhook.site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3d/
    webhook.site/c29905ab-e5fa-446c-8958-4eab15d8fb80/
    webhook.site/c2e1be16-401b-4f60-8a0f-276b30417fda/
    webhook.site/d63049e3-1cbe-474b-9005-237517af53a7/

  8. 1 domainthis year

    x.com/smica83/status/2020539423285203102 · virustotal.com/gui/file/506e7512c897514e9d312a1532d2e2…

    48d83469-d0c6-4ade-8f82-e383fff094b8.webhook.site

  9. 1 domainthis year

    x.com/smica83/status/2018659460261318958 · virustotal.com/gui/file/be859b4f4576ec09b69a2ef2d11993…

    longsauce.com

  10. 3 domainthis year

    x.com/HaifeiLi/status/2018353377965723761 · x.com/_CERT_UA/status/2018240505218314369 · pub.expmon.com/analysis/311631 · zscaler.com/blogs/security-research/apt28-leverages… · virustotal.com/gui/file/1ed863a32372160b3a25549aad25d4… · virustotal.com/gui/file/b2ba51b4491da8604ff9410d6e0049… · virustotal.com/gui/file/fed537aade989abe4eb76a7a27756e… · virustotal.com/gui/file/5a17cfaea0cc3a82242fdd11b53140… · virustotal.com/gui/file/c91183175ce77360006f964841eb40… · virustotal.com/gui/file/969d2776df0674a1cca0f74c2fccbc… · virustotal.com/gui/file/c9b3ef44640e0fe297d76e770454ee… · virustotal.com/gui/file/fd3f13db41cd5b442fa26ba8bc0e97…

    freefoodaid.com
    wellnesscaremed.com
    wellnessmedcare.org

  11. or earlier 1 ipv4, 1 urlthis year

    cert.gov.ua/article/6284730 (# lamehug) · app.any.run/tasks/5bd56fb0-573e-471c-8503-6fe1a7f86… · virustotal.com/gui/file/d6af1c9f5ce407e53ec73c8e7187ed… · virustotal.com/gui/file/bdb33bbb4ea11884b15f67e5c97413…

    ipv4144.126.202.227:22
    urlstayathomeclasses.com/slpw/up.php

  12. or earlier 1 urlthis year

    kroll.com/en/publications/cyber/fancy-bear-gonepo…

    webhook.site/8bf50371-5f9f-4d45-9320-922b068ebc2e

  13. 2 domain, 1 url1 yr ago

    x.com/StrikeReadyLabs/status/1878779709590565… · virustotal.com/gui/file/53142380d75e3f54490f2896b58f30…

    domaindoads.org
    domainlinkcuts.com
    urlrun.mocky.io/v3/22a2a2d8-84b9-4619-b8ba-359beb386cf9

  14. 9 domain2 yrs ago

    community.emergingthreats.net/t/ruleset-update-summary-2024-11-21-v10…

    errorreporting.net
    experience-improvement.com
    game-wins.com
    internalsecurity.us
    lanmangraphics.com
    retaildemo.info
    shared-rss.info
    telemetry-network.com
    tieringservice.com

  15. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1857059598072455… · virustotal.com/gui/file/44935484933a13fb6632e8db92229c…

    tuyt8erti867i.synergize.co

  16. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1853769628696113… · virustotal.com/gui/file/be3cccc2c62c0033aebcf91a6587eb…

    chujdrtuityui.mydiscussion.net

  17. 1 domain, 1 url2 yrs ago

    strikeready.com/blog/finding-the-unknown-unknowns-part-1

    domainkjghfkfgfdytku.infinityfreeapp.com
    urlrun.mocky.io/v3/da384ab3-f749-42d5-a076-40c248dece9b

  18. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1852167112367689…

    ukrainesafe.is-great.org

  19. 1 domain2 yrs ago

    x.com/StrikeReadyLabs/status/1851266545793617… · virustotal.com/gui/file/fa8a4d544ffb3ca9d51448772f478f…

    ukrainesafeurl.talebco.ir

  20. 4 domain, 4 ipv42 yrs ago

    cert.gov.ua/article/6281123 (# UAC-0001) · hunt.io/blog/operation-roundish-apt28-roundcube…

    domaindoc.gmail.com.gyehddhrggdii323sdhnshiswh2udhqjwdhhfjcjeuejcj.zhblz.com
    domaindocs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz.com
    domainmail.zhblz.com
    domainzhblz.com
    ipv4203.161.50.145:22
    ipv4203.161.50.145:6211
    ipv4203.161.50.145:8443
    ipv445.61.169.221:445

  21. 1 domain, 1 ipv42 yrs ago

    x.com/StrikeReadyLabs/status/1849084042966094… · virustotal.com/gui/file/a097400e060edf1190002a30c64506…

    domainukraine.html-5.me
    ipv43.67.15.169:1746

  22. 1 domain2 yrs ago

    virustotal.com/gui/file/86a9ca34790e219ddc371fa154c51a…

    fghjdfhdzggjjdfd.rf.gd

  23. 1 domain, 2 url2 yrs ago

    x.com/Cyber0verload/status/1841924570351018233

    domainvgjkifguotgi.talebco.ir
    urlrun.mocky.io/v3/8dbd585e-805d-4b14-8485-c6da4c3ef5a7
    urlrun.mocky.io/v3/df8e33e0-4c17-4564-917f-9fbff17f4571

  24. 2 domain, 1 ipv4, 1 url2 yrs ago

    x.com/StrikeReadyLabs/status/1841288172950499… · virustotal.com/gui/file/1bcc09d482a1c84a06c4f1da85ba90… · virustotal.com/gui/file/3d165a9bd4738fd3c1922643bd4520…

    domainjkbfgkjdffghh.linkpc.net
    domainjkcfgjgfcjty.fast-page.org
    ipv418.197.239.109:10176
    urlrun.mocky.io/v3/6ba09505-fa73-4d92-b209-641bfc51b6e2

  25. 2 domain, 1 url2 yrs ago

    x.com/StrikeReadyLabs/status/1837316398760022… · virustotal.com/gui/file/8b77e8199c61c0d97b7a40e35feedf…

    domain47e811dbe2ed0ea8d506af94c1bb7d4c.serveo.net
    domainfgjgjuyfkuuyk.blogspot.com
    urlrun.mocky.io/v3/6c446a45-05aa-4198-9a81-d4472d7e81cb

  26. 1 url2 yrs ago

    x.com/StrikeReadyLabs/status/1834217191060779… · x.com/Cyber0verload/status/1834259021060014302

    run.mocky.io/v3/47d78e98-8d12-452a-922b-bae56450a393

  27. 1 domain, 2 ipv42 yrs ago

    x.com/StrikeReadyLabs/status/1830933284248776… · virustotal.com/gui/file/f112876e875d43791da675e1187254… · virustotal.com/gui/file/64b26a92652bfb67cbe18217b6508f…

    domainkfghjerrlknsm.line.pm
    ipv418.157.68.73:15254
    ipv418.192.93.86:11962

  28. 9 domain2 yrs ago

    x.com/RakeshKrish12/status/1830493704911728980

    cluz.someguydelivery.com
    dryf.shneez.com
    igfcw.torresemello.com
    jzit.wocircuitfitness.com
    majc.healthfloww.com
    swvfy.noreplay-fca.com
    urjaa.nitrocreditfix.com
    uttlh.peterswaysales.com
    zxrgh.viouni.com

  29. 2 domain2 yrs ago

    x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1829562262253617… · virustotal.com/gui/file/98a97978f84a2ca6f2c05a4e15e60e… · virustotal.com/gui/file/654a19f0773bbba1e63b0fee936b26…

    6c7aa72bd5f1d30203b80596f926b2b7.serveo.net
    78cc700b31dcd7c7f25fd7b0372259e3.serveo.net

  30. 1 url2 yrs ago

    x.com/Tac_Mangusta/status/1828077900475580901 · virustotal.com/gui/file/aaa20b39bcf056f42509069dc3facc…

    http://83.147.243.18

  31. 1 domain2 yrs ago

    x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1826585308734931… · x.com/StrikeReadyLabs/status/1826950349384495… · virustotal.com/gui/file/c194f619d1ed73c0f0721d818564aa… · virustotal.com/gui/file/2431578b5ba5a8569a689807bdb827…

    73ce1aae8a9ba738b91040232524f51a.serveo.net

  32. 1 domain2 yrs ago

    twitter.com/Joseliyo_Jstnk/status/17696994420456572… · x.com/Joseliyo_Jstnk/status/18268796529603464… · securityintelligence.com/x-force/itg05-leverages-malware-arsenal · virustotal.com/gui/file/18f891a3737bb53cd1ab451e214065… · virustotal.com/gui/file/40a7fd89b9e51b0a515ac2355036d2… · virustotal.com/gui/file/451f3d427ac21632f38619ef96dece… · virustotal.com/gui/file/64b0037dde987c78edf807a1bd7f09…

    eecomission.firstcloudit.com

  33. 1 domain2 yrs ago

    x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1826585308734931… · x.com/StrikeReadyLabs/status/1826950349384495… · virustotal.com/gui/file/c194f619d1ed73c0f0721d818564aa… · virustotal.com/gui/file/2431578b5ba5a8569a689807bdb827…

    92ace7e653e9c32d2af9700592cc96ea.serveo.net

  34. 2 url2 yrs ago

    unit42.paloaltonetworks.com/fighting-ursa-car-for-sale-phishing-lure

    webhook.site/66d5b9f9-a5eb-48e6-9476-9b6142b0c3ae
    webhook.site/d290377c-82b5-4765-acb8-454edf6425dd

  35. 7 domain, 1 ipv4, 1 url2 yrs ago

    twitter.com/BushidoToken/status/1740431013397078407 · twitter.com/k3yp0d/status/1752285465284170186 · cert.gov.ua/article/6276894 · harfanglab.io/en/insidethelab/compromised-routers-inf… · otx.alienvault.com/pulse/65bcd6e5cc24f8906b1a212a

    domaincn5n8a92vtc00004a0t0gks3tbcyyyyyd.oast.fun
    domainczyrqdnvpujmmjkfhhvs2x9oyfsn6gd7t.oast.fun
    domainczyrqdnvpujmmjkfhhvs9647ioh30wxvd.oast.fun
    domainczyrqdnvpujmmjkfhhvseabz1q5olrum5.oast.fun
    domainczyrqdnvpujmmjkfhhvsqfxkqz68qzjcd.oast.fun
    domainczyrqdnvpujmmjkfhhvsqslblw0mawilr.oast.fun
    domaine-wody.firstcloudit.com

    · 2 more in this batch, in the JSON

Further reading 319

279 more, and the report behind every indicator, in G0007.json.