G0007
G0007APT28
Description
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019)
[APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election. (Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).
References
- https://attack.mitre.org/groups/G0007
- https://www.accenture.com/t20181129T203820Z__w__/us-en/_acnmedia/PDF-90/Accenture-snakemackerel-delivers-zekapab-malware.pdf#zoom=50
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
- https://www.justice.gov/opa/page/file/1098481/download
- https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296A_GRIZZLY%20STEPPE-2016-1229.pdf
- https://www.welivesecurity.com/2019/05/22/journey-zebrocy-land/
- http://www.welivesecurity.com/wp-content/uploads/2016/10/eset-sednit-part3.pdf
- https://researchcenter.paloaltonetworks.com/2018/03/unit42-sofacy-uses-dealerschoice-target-european-government-agency/
- https://www2.fireeye.com/rs/848-DID-242/images/APT28-Center-of-Storm-2017.pdf
- https://web.archive.org/web/20151022204649/https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf
Software attributed to this13
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Software | Zebrocys0251 | 100% | live |
| Software | JHUHUGITs0044 | 100% | live |
| Software | Komplexs0162 | 100% | live |
| Software | CORESHELLs0137 | 100% | live |
| Software | XTunnels0117 | 100% | live |
| Software | CHOPSTICKs0023 | 100% | live |
| Software | OLDBAITs0138 | 100% | live |
| Software | USBStealers0136 | 100% | live |
| Software | Fysbiss0410 | 100% | live |
| Software | ADVSTORESHELLs0045 | 100% | live |
| Software | Drovorubs0502 | 95% | live |
| Software | Downdelphs0134 | 95% | live |
| Software | XAgentOSXs0161 | 95% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.