G0007

G0007APT28

Description

[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. (Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).

References

  1. https://attack.mitre.org/groups/G0007
  2. https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf#zoom=50
  3. https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
  4. https://www.justice.gov/opa/page/file/1098481/download
  5. https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296A_GRIZZLY%20STEPPE-2016-1229.pdf
  6. https://www.welivesecurity.com/2019/05/22/journey-zebrocy-land/
  7. http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part3.pdf
  8. https://researchcenter.paloaltonetworks.com/2018/03/unit42-sofacy-uses-dealerschoice-target-european-government-agency/
  9. https://www2.fireeye.com/rs/848-DID-242/images/APT28-Center-of-Storm-2017.pdf
  10. https://web.archive.org/web/20151022204649/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf

Software attributed to this13

TypeTargetConfidenceTier
SoftwareZebrocys0251100%live
SoftwareJHUHUGITs0044100%live
SoftwareKomplexs0162100%live
SoftwareCORESHELLs0137100%live
SoftwareXTunnels0117100%live
SoftwareCHOPSTICKs0023100%live
SoftwareOLDBAITs0138100%live
SoftwareUSBStealers0136100%live
SoftwareFysbiss0410100%live
SoftwareADVSTORESHELLs0045100%live
SoftwareDrovorubs050295%live
SoftwareDowndelphs013495%live
SoftwareXAgentOSXs016195%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT29
Group
Sandworm Team
Group
APT17
Actor
APT27
Group
APT18
Group
APT19
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.