Threat group.View on attack.mitre.org
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004.
APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire. |
| T1003 OS Credential Dumping |
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. |
| T1003.001 LSASS Memory |
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function. |
| T1003.003 NTDS |
APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access. |
| T1005 Data from Local System |
APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration. |
| T1014 Rootkit |
APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax. |
| T1021.002 SMB/Windows Admin Shares |
APT28 has mapped network drives using Net and administrator credentials. |
| T1025 Data from Removable Media |
An APT28 backdoor may collect the entire contents of an inserted USB device. |
| T1027.013 Encrypted/Encoded File |
APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| T1030 Data Transfer Size Limits |
APT28 has split archived exfiltration files into chunks smaller than 1MB. |
| T1036 Masquerading |
APT28 has renamed the WinRAR utility to avoid detection. |
| T1036.005 Match Legitimate Resource Name or Location |
APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page. |
| T1037.001 Logon Script (Windows) |
An APT28 loader Trojan adds the Registry key |
| T1039 Data from Network Shared Drive |
APT28 has collected files from network shared drives. |
| T1040 Network Sniffing |
APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.