ATT&CKCampaignsAPT28 Nearest Neighbor Campaign

APT28 Nearest Neighbor Campaign

C0051

Campaign, Feb 2022 to Nov 2024.View on attack.mitre.org

About this campaign

APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1003.002
Security Account Manager

During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: reg save hklm\sam, reg save hklm\system, and reg save hklm\security.

T1003.003
NTDS

During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via vssadmin.

T1006
Direct Volume Access

During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing vssadmin in order to dump the NTDS.dit file.

T1016.002
Wi-Fi Discovery

During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system.

T1021.001
Remote Desktop Protocol

During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement.

T1021.002
SMB/Windows Admin Shares

During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally.

T1059.001
PowerShell

During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet Get-ChildItem to access credentials, among other PowerShell functions deployed.

T1059.003
Windows Command Shell

During APT28 Nearest Neighbor Campaign, APT28 used cmd.exe for execution.

T1074.001
Local Data Staging

During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the C:\ProgramData directory.

T1090.001
Internal Proxy

During APT28 Nearest Neighbor Campaign, APT28 used the built-in netsh portproxy command to create internal proxies on compromised systems.

T1110.003
Password Spraying

During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials.

T1140
Deobfuscate/Decode Files or Information

During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR.

T1560.001
Archive via Utility

During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data.

T1561.001
Disk Content Wipe

During APT28 Nearest Neighbor Campaign, APT28 used the native Microsoft utility cipher.exe to securely wipe files and folders – overwriting the deleted data using cmd.exe /c cipher /W:C.

T1567
Exfiltration Over Web Service

During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive.

View all 18 procedure examples

Attributed groups1

Software2

References1

  1. Nearest Neighbor Volexity Open source
    Koessel, Sean. Adair, Steven. Lancaster, Tom. (2024, November 22). The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access. Retrieved February 25, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.