APT28

G0007

Threat group.View on attack.mitre.org

About this group

APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004.

APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.

Techniques used93

Procedure examples93

TechniqueProcedure example
T1001.001
Junk Data

APT28 added "junk data" to each encoded string, preventing trivial decoding without knowledge of the junk removal algorithm. Each implant was given a "junk length" value when created, tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire.

T1003
OS Credential Dumping

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims.

T1003.001
LSASS Memory

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1003.003
NTDS

APT28 has used the ntdsutil.exe utility to export the Active Directory database for credential access.

T1005
Data from Local System

APT28 has retrieved internal documents from machines inside victim environments, including by using Forfiles to stage documents before exfiltration.

T1014
Rootkit

APT28 has used a UEFI (Unified Extensible Firmware Interface) rootkit known as LoJax.

T1021.002
SMB/Windows Admin Shares

APT28 has mapped network drives using Net and administrator credentials.

T1025
Data from Removable Media

An APT28 backdoor may collect the entire contents of an inserted USB device.

T1027.013
Encrypted/Encoded File

APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4.

T1030
Data Transfer Size Limits

APT28 has split archived exfiltration files into chunks smaller than 1MB.

T1036
Masquerading

APT28 has renamed the WinRAR utility to avoid detection.

T1036.005
Match Legitimate Resource Name or Location

APT28 has changed extensions on files containing exfiltrated data to make them appear benign, and renamed a web shell instance to appear as a legitimate OWA page.

T1037.001
Logon Script (Windows)

An APT28 loader Trojan adds the Registry key HKCU\Environment\UserInitMprLogonScript to establish persistence.

T1039
Data from Network Shared Drive

APT28 has collected files from network shared drives.

T1040
Network Sniffing

APT28 deployed the open source tool Responder to conduct NetBIOS Name Service poisoning, which captured usernames and hashed passwords that allowed access to legitimate credentials. APT28 close-access teams have used Wi-Fi pineapples to intercept Wi-Fi signals and user credentials.

View all 93 procedure examples

Software29

Show 5 more

Campaigns1

References14

  1. Ars Technica GRU indictment Jul 2018 Open source
    Gallagher, S. (2018, July 27). How they did it (and will likely try again): GRU hackers vs. US elections. Retrieved September 13, 2018.
  2. Crowdstrike DNC June 2016 Open source
    Alperovitch, D.. (2016, June 15). Bears in the Midst: Intrusion into the Democratic National Committee. Retrieved August 3, 2016.
  3. Cybersecurity Advisory GRU Brute Force Campaign July 2021 Open source
    NSA, CISA, FBI, NCSC. (2021, July). Russian GRU Conducting Global Brute Force Campaign to Compromise Enterprise and Cloud Environments. Retrieved July 26, 2021.
  4. DOJ GRU Indictment Jul 2018 Open source
    Mueller, R. (2018, July 13). Indictment - United States of America vs. VIKTOR BORISOVICH NETYKSHO, et al. Retrieved November 17, 2024.
  5. ESET Zebrocy May 2019 Open source
    ESET Research. (2019, May 22). A journey to Zebrocy land. Retrieved June 20, 2019.
  6. FireEye APT28 Open source
    FireEye. (2015). APT28: A WINDOW INTO RUSSIA’S CYBER ESPIONAGE OPERATIONS?. Retrieved August 19, 2015.
  7. FireEye APT28 January 2017 Open source
    FireEye iSIGHT Intelligence. (2017, January 11). APT28: At the Center of the Storm. Retrieved November 17, 2024.
  8. GRIZZLY STEPPE JAR Open source
    Department of Homeland Security and Federal Bureau of Investigation. (2016, December 29). GRIZZLY STEPPE – Russian Malicious Cyber Activity. Retrieved January 11, 2017.
  9. NSA/FBI Drovorub August 2020 Open source
    NSA/FBI. (2020, August). Russian GRU 85th GTsSS Deploys Previously Undisclosed Drovorub Malware. Retrieved August 25, 2020.
  10. Palo Alto Sofacy 06-2018 Open source
    Lee, B., Falcone, R. (2018, June 06). Sofacy Group’s Parallel Attacks. Retrieved June 18, 2018.
  11. SecureWorks TG-4127 Open source
    SecureWorks Counter Threat Unit Threat Intelligence. (2016, June 16). Threat Group-4127 Targets Hillary Clinton Presidential Campaign. Retrieved August 3, 2016.
  12. Sofacy DealersChoice Open source
    Falcone, R. (2018, March 15). Sofacy Uses DealersChoice to Target European Government Agency. Retrieved June 4, 2018.
  13. Symantec APT28 Oct 2018 Open source
    Symantec Security Response. (2018, October 04). APT28: New Espionage Operations Target Military and Government Organizations. Retrieved November 14, 2018.
  14. US District Court Indictment GRU Oct 2018 Open source
    Brady, S . (2018, October 3). Indictment - United States vs Aleksei Sergeyevich Morenets, et al.. Retrieved October 1, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.