Overview 1,894 indicators
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
| domain | 1,431 | G0007-domain.txt |
| ipv4 | 240 | G0007.json |
| url | 144 | G0007.json |
| url_path | 79 | G0007.json |
Techniques 95 ATT&CK
Open in ATT&CK Navigator → or download the layer (95 techniques, layer 4.5)
- T1001.001 Junk Data
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1003.003 NTDS
- T1005 Data from Local System
- T1014 Rootkit
- T1021.002 SMB/Windows Admin Shares
- T1025 Data from Removable Media
- T1027.013 Encrypted/Encoded File
- T1030 Data Transfer Size Limits
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1037.001 Logon Script (Windows)
- T1039 Data from Network Shared Drive
- T1040 Network Sniffing
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1071.003 Mail Protocols
- T1074.001 Local Data Staging
- T1074.002 Remote Data Staging
- T1078 Valid Accounts
- T1078.004 Cloud Accounts
- T1083 File and Directory Discovery
- T1090.002 External Proxy
- T1090.003 Multi-hop Proxy
- T1091 Replication Through Removable Media
- T1092 Communication Through Removable Media
- T1098.002 Additional Email Delegate Permissions
- T1102.002 Bidirectional Communication
- T1105 Ingress Tool Transfer
- T1110 Brute Force
- T1110.001 Password Guessing
- T1110.003 Password Spraying
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1119 Automated Collection
- T1120 Peripheral Device Discovery
- T1133 External Remote Services
- T1134.001 Token Impersonation/Theft
- T1137.002 Office Test
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1199 Trusted Relationship
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1210 Exploitation of Remote Services
- T1211 Exploitation for Stealth
- T1213 Data from Information Repositories
- T1213.002 Sharepoint
- T1218.011 Rundll32
- T1221 Template Injection
- T1328 Buy domain name
- T1346 Obtain/re-use payloads
- T1498 Network Denial of Service
- T1505.003 Web Shell
- T1528 Steal Application Access Token
- T1542.003 Bootkit
- T1546.015 Component Object Model Hijacking
- T1547.001 Registry Run Keys / Startup Folder
- T1550.001 Application Access Token
- T1550.002 Pass the Hash
- T1557.004 Evil Twin
- T1559.002 Dynamic Data Exchange
- T1560 Archive Collected Data
- T1560.001 Archive via Utility
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1567 Exfiltration Over Web Service
- T1573.001 Symmetric Cryptography
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1583.006 Web Services
- T1584.008 Network Devices
- T1586.002 Email Accounts
- T1588.002 Tool
- T1588.007 Artificial Intelligence
- T1589.001 Credentials
- T1591 Gather Victim Org Information
- T1595.002 Vulnerability Scanning
- T1596 Search Open Technical Databases
- T1598 Phishing for Information
- T1598.003 Spearphishing Link
- T1669 Wi-Fi Networks
- T1684.001 Impersonation
- T1685.005 Clear Windows Event Logs
Software 30
- Mimikatz
- CHOPSTICK
- Net
- JHUHUGIT
- ADVSTORESHELL
- XTunnel
- Downdelph
- HIDEDRV
- USBStealer
- CORESHELL
- OLDBAIT
- certutil
- XAgentOSX
- Komplex
- Responder
- Tor
- Winexe
- Forfiles
- DealersChoice
- Koadic
- Zebrocy
- X-Agent for Android
- Cannon
- LoJax
- Fysbis
- Drovorub
- Wevtutil
- reGeorg
- cipher.exe
- LAMEHUG
Principal sources 301 reports
Ranked by how many of this actor's indicators each report brought in.
- 356tr1adx.net/intel/public/TIB-00001_IOC_Domain.txt
- 216threatconnect.com/finding-nemohost-fancy-bear-infrastruct…
- 205pwc.blogs.com/files/tactical-intelligence-bulletin---…
- 182ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dn…
- 89threatconnect.com/blog/fancy-bear-leverages-blogspot
- 77welivesecurity.com/2018/04/24/sednit-update-analysis-zebro…
- 64threatconnect.com/blog/how-to-investigate-incidents-in-th…
- 54documents.trendmicro.com/assets/appendix_looking-into-a-cyber-at…
Related groups 21
What the sources have in common — not a claim that these are the same actor. See the whole graph.
13 more in the relationship graph.
Timeline 1,894 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 1,894. Complete: G0007.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dn…
103.140.186.148:53 103.140.186.149:53 103.140.186.155:53 185.117.88.22:53 185.117.88.28:53 185.117.88.29:53 185.117.88.30:53 185.117.88.31:53 185.117.88.50:53 185.117.88.60:53 185.117.88.61:53 185.117.88.62:53 185.117.89.32:53 185.117.89.46:53 185.117.89.47:53 185.234.73.58:53 185.234.73.61:53 185.234.73.62:53 185.237.166.224:53 185.237.166.225:53 185.237.166.226:53 185.237.166.227:53 185.237.166.228:53 185.237.166.229:53 185.237.166.230:53 185.237.166.231:53 185.237.166.232:53 185.237.166.233:53 185.237.166.234:53 185.237.166.235:53 185.237.166.236:53 185.237.166.237:53 185.237.166.238:53 185.237.166.239:53 185.237.166.240:53 185.237.166.241:53 185.237.166.242:53 185.237.166.243:53 185.237.166.244:53 185.237.166.245:53 185.237.166.246:53 185.237.166.247:53 185.237.166.248:53 185.237.166.249:53 185.237.166.55:53 185.237.166.56:53 185.237.166.57:53 185.237.166.58:53 185.237.166.59:53 185.237.166.60:53 185.237.166.61:53 185.237.166.62:53 185.237.166.63:53 185.237.166.64:53 185.237.166.65:53 185.237.166.66:53 185.237.166.67:53 185.237.166.68:53 185.237.166.69:53 185.237.166.70:53 185.237.166.71:53 185.237.166.72:53 185.237.166.73:53 185.237.166.74:53 185.237.166.75:53 23.106.120.119:53 37.221.64.101:53 37.221.64.116:53 37.221.64.131:53 37.221.64.148:53 37.221.64.149:53 37.221.64.150:53 37.221.64.151:53 37.221.64.163:53 37.221.64.173:53 37.221.64.199:53 37.221.64.208:53 37.221.64.224:53 37.221.64.254:53 37.221.64.77:53 37.221.64.78:53 37.221.64.93:53 5.226.137.151:53 5.226.137.230:53 5.226.137.231:53 5.226.137.232:53 5.226.137.234:53 5.226.137.235:53 5.226.137.242:53 5.226.137.243:53 5.226.137.244:53 5.226.137.245:53 64.120.31.100:53 64.120.31.96:53 64.120.31.97:53 64.120.31.98:53 64.120.31.99:53 64.44.154.227:53 64.44.154.237:53 64.44.154.238:53 64.44.154.239:53 64.44.154.240:53 77.83.197.37:53 77.83.197.38:53 77.83.197.39:53 77.83.197.40:53 77.83.197.41:53 77.83.197.42:53 77.83.197.43:53 77.83.197.44:53 77.83.197.45:53 77.83.197.46:53 77.83.197.47:53 77.83.197.48:53 77.83.197.49:53 77.83.197.50:53 77.83.197.51:53 77.83.197.52:53 77.83.197.53:53 77.83.197.54:53 77.83.197.55:53 77.83.197.56:53 77.83.197.57:53 77.83.197.58:53 77.83.197.59:53 77.83.197.60:53 77.83.198.39:53 79.141.160.78:53 79.141.161.66:53 79.141.161.67:53 79.141.161.68:53 79.141.161.69:53 79.141.161.70:53 79.141.161.71:53 79.141.161.72:53 79.141.161.73:53 79.141.161.74:53 79.141.161.75:53 79.141.161.76:53 79.141.161.77:53 79.141.161.78:53 79.141.161.79:53 79.141.161.80:53 79.141.161.81:53 79.141.161.82:53 79.141.161.83:53 79.141.161.84:53 79.141.161.85:53 79.141.173.103:53 79.141.173.119:53 79.141.173.120:53 79.141.173.121:53 79.141.173.122:53 79.141.173.123:53 79.141.173.200:53 79.141.173.210:53 79.141.173.211:53 79.141.173.231:53 79.141.173.232:53 79.141.173.233:53 79.141.173.246:53 79.141.173.247:53 79.141.173.248:53 79.141.173.249:53 79.141.173.250:53 79.141.173.251:53 79.141.173.252:53 79.141.173.253:53 79.141.173.254:53 79.141.173.70:53 79.141.173.96:53 79.141.173.97:53 79.141.173.98:53 79.143.87.229:53 79.143.87.232:53 79.143.87.240:53 79.143.87.243:53 79.143.87.249:53 88.80.148.49:53 88.80.148.53:53 89.150.40.43:53 89.150.40.86:53 -
x.com/smica83/status/2037477379530953027 · virustotal.com/gui/file/479fd5e5bd5566a0252acd4ec29c5a…
webhook.site/c2dceeb0-d40d-41a2-8622-118fa974649c/ -
trendmicro.com/en_us/research/26/c/pawn-storm-targets-… · documents.trendmicro.com/assets/txt/Pawn%20Storm%20Deploys%20PRI…
910cf351-a05d-4f67-ab8e-6f62cfa8e26d.dnshook.site dbca10b5-63e0-42ec-ad10-de13be96dc42.dnshook.site -
x.com/TeamDreier/status/2035301205031719170 · seqrite.com/blog/operation-ghostmail-zimbra-xss-rus… · proofpoint.com/us/blog/threat-insight/ta488-targets-zi…
analyticemailmeter.com emailanalytics.com.ua fraispei.com ftp.fraispei.com i.analyticemailmeter.com i.emailanalytics.com.ua i.mailnalysis.com i.zimbra-metadata.com i.zimbrasoft.com.ua i.zimbrastat.com i.zmailanalytics.com istc-cloud.com mailnalysis.com pro.fraispei.com synacorzimbra.nl test.fraispei.com zimbra-metadata.com zimbrasoft.com.ua zimbrastat.com zmailanalytics.com -
ctrlaltintel.com/threat%20research/FancyBear
gov.vppdr.com vppdr.com -
cert.gov.ua/article/6281123 (# UAC-0001) · hunt.io/blog/operation-roundish-apt28-roundcube…
domain a.zhblz.com domain ns1.petdiary.net domain ns2.petdiary.net domain petdiary.net ipv4 203.161.50.145:5000 ipv4 203.161.50.145:8080 ipv4 203.161.50.145:8889 url http://93.170.72.54 -
x.com/LAB52io/status/2022281566513180933 · virustotal.com/gui/file/9097d9cf5e6659e869bf2edf766741…
webhook.site/4e6cf717-e4d6-4f40-9f2d-134196fa5e7d/ webhook.site/5744c020-a8d9-4755-abfb-cde6ccd450af/ webhook.site/5dbed3be-f1c9-41e5-b5d5-e961d08b5fba/ webhook.site/62114596-33f5-47fb-9012-0223529e5a13/ webhook.site/68d68fc7-aa94-4f2d-a727-d18fb40b0d69/ webhook.site/a3f4e990-0b2a-4f6a-a02e-c573005de3ee/ webhook.site/a72d8905-b15f-4e95-9a8f-5e4bb7dc9b3d/ webhook.site/c29905ab-e5fa-446c-8958-4eab15d8fb80/ webhook.site/c2e1be16-401b-4f60-8a0f-276b30417fda/ webhook.site/d63049e3-1cbe-474b-9005-237517af53a7/ -
x.com/smica83/status/2020539423285203102 · virustotal.com/gui/file/506e7512c897514e9d312a1532d2e2…
48d83469-d0c6-4ade-8f82-e383fff094b8.webhook.site -
x.com/smica83/status/2018659460261318958 · virustotal.com/gui/file/be859b4f4576ec09b69a2ef2d11993…
longsauce.com -
x.com/HaifeiLi/status/2018353377965723761 · x.com/_CERT_UA/status/2018240505218314369 · pub.expmon.com/analysis/311631 · zscaler.com/blogs/security-research/apt28-leverages… · virustotal.com/gui/file/1ed863a32372160b3a25549aad25d4… · virustotal.com/gui/file/b2ba51b4491da8604ff9410d6e0049… · virustotal.com/gui/file/fed537aade989abe4eb76a7a27756e… · virustotal.com/gui/file/5a17cfaea0cc3a82242fdd11b53140… · virustotal.com/gui/file/c91183175ce77360006f964841eb40… · virustotal.com/gui/file/969d2776df0674a1cca0f74c2fccbc… · virustotal.com/gui/file/c9b3ef44640e0fe297d76e770454ee… · virustotal.com/gui/file/fd3f13db41cd5b442fa26ba8bc0e97…
freefoodaid.com wellnesscaremed.com wellnessmedcare.org -
cert.gov.ua/article/6284730 (# lamehug) · app.any.run/tasks/5bd56fb0-573e-471c-8503-6fe1a7f86… · virustotal.com/gui/file/d6af1c9f5ce407e53ec73c8e7187ed… · virustotal.com/gui/file/bdb33bbb4ea11884b15f67e5c97413…
ipv4 144.126.202.227:22 url stayathomeclasses.com/slpw/up.php -
kroll.com/en/publications/cyber/fancy-bear-gonepo…
webhook.site/8bf50371-5f9f-4d45-9320-922b068ebc2e -
x.com/StrikeReadyLabs/status/1878779709590565… · virustotal.com/gui/file/53142380d75e3f54490f2896b58f30…
domain doads.org domain linkcuts.com url run.mocky.io/v3/22a2a2d8-84b9-4619-b8ba-359beb386cf9 -
community.emergingthreats.net/t/ruleset-update-summary-2024-11-21-v10…
errorreporting.net experience-improvement.com game-wins.com internalsecurity.us lanmangraphics.com retaildemo.info shared-rss.info telemetry-network.com tieringservice.com -
x.com/StrikeReadyLabs/status/1857059598072455… · virustotal.com/gui/file/44935484933a13fb6632e8db92229c…
tuyt8erti867i.synergize.co -
x.com/StrikeReadyLabs/status/1853769628696113… · virustotal.com/gui/file/be3cccc2c62c0033aebcf91a6587eb…
chujdrtuityui.mydiscussion.net -
strikeready.com/blog/finding-the-unknown-unknowns-part-1
domain kjghfkfgfdytku.infinityfreeapp.com url run.mocky.io/v3/da384ab3-f749-42d5-a076-40c248dece9b -
x.com/StrikeReadyLabs/status/1852167112367689…
ukrainesafe.is-great.org -
x.com/StrikeReadyLabs/status/1851266545793617… · virustotal.com/gui/file/fa8a4d544ffb3ca9d51448772f478f…
ukrainesafeurl.talebco.ir -
cert.gov.ua/article/6281123 (# UAC-0001) · hunt.io/blog/operation-roundish-apt28-roundcube…
domain doc.gmail.com.gyehddhrggdii323sdhnshiswh2udhqjwdhhfjcjeuejcj.zhblz.com domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz.com domain mail.zhblz.com domain zhblz.com ipv4 203.161.50.145:22 ipv4 203.161.50.145:6211 ipv4 203.161.50.145:8443 ipv4 45.61.169.221:445 -
x.com/StrikeReadyLabs/status/1849084042966094… · virustotal.com/gui/file/a097400e060edf1190002a30c64506…
domain ukraine.html-5.me ipv4 3.67.15.169:1746 -
virustotal.com/gui/file/86a9ca34790e219ddc371fa154c51a…
fghjdfhdzggjjdfd.rf.gd -
x.com/Cyber0verload/status/1841924570351018233
domain vgjkifguotgi.talebco.ir url run.mocky.io/v3/8dbd585e-805d-4b14-8485-c6da4c3ef5a7 url run.mocky.io/v3/df8e33e0-4c17-4564-917f-9fbff17f4571 -
x.com/StrikeReadyLabs/status/1841288172950499… · virustotal.com/gui/file/1bcc09d482a1c84a06c4f1da85ba90… · virustotal.com/gui/file/3d165a9bd4738fd3c1922643bd4520…
domain jkbfgkjdffghh.linkpc.net domain jkcfgjgfcjty.fast-page.org ipv4 18.197.239.109:10176 url run.mocky.io/v3/6ba09505-fa73-4d92-b209-641bfc51b6e2 -
x.com/StrikeReadyLabs/status/1837316398760022… · virustotal.com/gui/file/8b77e8199c61c0d97b7a40e35feedf…
domain 47e811dbe2ed0ea8d506af94c1bb7d4c.serveo.net domain fgjgjuyfkuuyk.blogspot.com url run.mocky.io/v3/6c446a45-05aa-4198-9a81-d4472d7e81cb -
x.com/StrikeReadyLabs/status/1834217191060779… · x.com/Cyber0verload/status/1834259021060014302
run.mocky.io/v3/47d78e98-8d12-452a-922b-bae56450a393 -
x.com/StrikeReadyLabs/status/1830933284248776… · virustotal.com/gui/file/f112876e875d43791da675e1187254… · virustotal.com/gui/file/64b26a92652bfb67cbe18217b6508f…
domain kfghjerrlknsm.line.pm ipv4 18.157.68.73:15254 ipv4 18.192.93.86:11962 -
x.com/RakeshKrish12/status/1830493704911728980
cluz.someguydelivery.com dryf.shneez.com igfcw.torresemello.com jzit.wocircuitfitness.com majc.healthfloww.com swvfy.noreplay-fca.com urjaa.nitrocreditfix.com uttlh.peterswaysales.com zxrgh.viouni.com -
x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1829562262253617… · virustotal.com/gui/file/98a97978f84a2ca6f2c05a4e15e60e… · virustotal.com/gui/file/654a19f0773bbba1e63b0fee936b26…
6c7aa72bd5f1d30203b80596f926b2b7.serveo.net 78cc700b31dcd7c7f25fd7b0372259e3.serveo.net -
x.com/Tac_Mangusta/status/1828077900475580901 · virustotal.com/gui/file/aaa20b39bcf056f42509069dc3facc…
http://83.147.243.18 -
x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1826585308734931… · x.com/StrikeReadyLabs/status/1826950349384495… · virustotal.com/gui/file/c194f619d1ed73c0f0721d818564aa… · virustotal.com/gui/file/2431578b5ba5a8569a689807bdb827…
73ce1aae8a9ba738b91040232524f51a.serveo.net -
twitter.com/Joseliyo_Jstnk/status/17696994420456572… · x.com/Joseliyo_Jstnk/status/18268796529603464… · securityintelligence.com/x-force/itg05-leverages-malware-arsenal · virustotal.com/gui/file/18f891a3737bb53cd1ab451e214065… · virustotal.com/gui/file/40a7fd89b9e51b0a515ac2355036d2… · virustotal.com/gui/file/451f3d427ac21632f38619ef96dece… · virustotal.com/gui/file/64b0037dde987c78edf807a1bd7f09…
eecomission.firstcloudit.com -
x.com/Cyber0verload/status/1829953345009672433 · x.com/StrikeReadyLabs/status/1826585308734931… · x.com/StrikeReadyLabs/status/1826950349384495… · virustotal.com/gui/file/c194f619d1ed73c0f0721d818564aa… · virustotal.com/gui/file/2431578b5ba5a8569a689807bdb827…
92ace7e653e9c32d2af9700592cc96ea.serveo.net -
unit42.paloaltonetworks.com/fighting-ursa-car-for-sale-phishing-lure
webhook.site/66d5b9f9-a5eb-48e6-9476-9b6142b0c3ae webhook.site/d290377c-82b5-4765-acb8-454edf6425dd -
twitter.com/BushidoToken/status/1740431013397078407 · twitter.com/k3yp0d/status/1752285465284170186 · cert.gov.ua/article/6276894 · harfanglab.io/en/insidethelab/compromised-routers-inf… · otx.alienvault.com/pulse/65bcd6e5cc24f8906b1a212a
domain cn5n8a92vtc00004a0t0gks3tbcyyyyyd.oast.fun domain czyrqdnvpujmmjkfhhvs2x9oyfsn6gd7t.oast.fun domain czyrqdnvpujmmjkfhhvs9647ioh30wxvd.oast.fun domain czyrqdnvpujmmjkfhhvseabz1q5olrum5.oast.fun domain czyrqdnvpujmmjkfhhvsqfxkqz68qzjcd.oast.fun domain czyrqdnvpujmmjkfhhvsqslblw0mawilr.oast.fun domain e-wody.firstcloudit.com · 2 more in this batch, in the JSON
Further reading 319
- welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-…
- arstechnica.com/information-technology/2018/07/from-bit…
- attack.mitre.org/groups/G0007
- blog.talosintelligence.com/2017/10/cyber-conflict-decoy-document.h…
- media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROV…
- msrc-blog.microsoft.com/2019/08/05/corporate-iot-a-path-to-intr…
- researchcenter.paloaltonetworks.com/2018/03/unit42-sofacy-uses-dealerschoic…
- researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-a…
- securelist.com/a-slice-of-2017-sofacy-activity/83930
- securelist.com/sofacy-apt-hits-high-profile-targets-wi…
- accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/…
- crowdstrike.com/blog/bears-midst-intrusion-democratic-n…
- fireeye.com/content/dam/fireeye-www/global/en/curre…
- justice.gov/file/1080281/download
- justice.gov/opa/page/file/1098481/download
- microsoft.com/security/blog/2020/09/10/strontium-dete…
- secureworks.com/research/threat-group-4127-targets-hill…
- symantec.com/blogs/election-security/apt28-espionage…
- us-cert.gov/sites/default/files/publications/JAR_16…
- welivesecurity.com/2019/05/22/journey-zebrocy-land
- www2.fireeye.com/rs/848-DID-242/images/APT28-Center-of-S…
- blog.yoroi.company/research/apt28-and-upcoming-elections-p…
- virustotal.com/gui/file/1ee602e9b6e4e58dfff0fb8606a413…
- twitter.com/dewan202/status/1107348923826491392
- x.com/StrikeReadyLabs/status/1837316398760022…
- virustotal.com/gui/file/aef94d2451e1eb943d2b1ee5ed48d9…
- meltx0r.github.io/tech/2019/10/24/apt28.html
- us-cert.cisa.gov/ncas/analysis-reports/ar20-303b
- x.com/StrikeReadyLabs/status/1829562262253617…
- app.any.run/tasks/9abe2703-3750-4728-a932-129177b2a…
- threatconnect.com/blog/using-fancy-bear-ssl-certificate-i…
- twitter.com/Joseliyo_Jstnk/status/17696994420456572…
- x.com/StrikeReadyLabs/status/1849084042966094…
- hexcapes.com/sofacy-in-poland
- researchcenter.paloaltonetworks.com/2016/12/unit42-let-ride-sofacy-groups-d…
- fireeye.com/blog/threat-research/2015/04/probable_a…
- twitter.com/VK_Intel/status/1075307666434600960
- otx.alienvault.com/pulse/5e736669fcc47a29220ce3f0
- welivesecurity.com/2018/04/24/sednit-update-analysis-zebro…
- s3.amazonaws.com/snort-org/www/rules/community/community…
279 more, and the report behind every indicator, in G0007.json.