Threat Actor Profile
Description
APT28is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.[1][2]This group has been active since at least 2004.[3][4][5][6][7][8][9][10][11][12][13] APT28reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.[5]In 2018, the US indicted five GRU Unit 26165 officers associated withAPT28for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.[14]Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to asSandworm Team.
Confidence Score
Tags
First Seen
Unknown
Last Updated
April 29, 2026
18 hours, 43 minutes ago
Active Status
ActiveCreated
April 29, 2026
MITRE ATT&CK Techniques (74)
Indicators of Compromise
Loading IOCs…
IOC KQL for Sentinel
STIX Data
{'aliases': [],
'description': "APT28is a threat group that has been attributed to Russia's "
'General Staff Main Intelligence Directorate (GRU) 85th Main '
'Special Service Center (GTsSS) military unit 26165.[1][2]This '
'group has been active since at least '
'2004.[3][4][5][6][7][8][9][10][11][12][13] APT28reportedly '
'compromised the Hillary Clinton campaign, the Democratic '
'National Committee, and the Democratic Congressional Campaign '
'Committee in 2016 in an attempt to interfere with the U.S. '
'presidential election.[5]In 2018, the US indicted five GRU '
'Unit 26165 officers associated withAPT28for cyber operations '
'(including close-access operations) conducted between 2014 '
'and 2018 against the World Anti-Doping Agency (WADA), the US '
'Anti-Doping Agency, a US nuclear facility, the Organization '
'for the Prohibition of Chemical Weapons (OPCW), the Spiez '
'Swiss Chemicals Laboratory, and other organizations.[14]Some '
'of these were conducted with the assistance of GRU Unit '
'74455, which is also referred to asSandworm Team.',
'external_references': [{'external_id': 'G0007',
'source_name': 'mitre-attack',
'url': 'https://attack.mitre.org/groups/G0007/'}],
'id': 'threat-actor--G0007',
'metadata': {'crawled_at': '2026-04-29T14:32:40.233243+00:00',
'mitre_group_id': 'G0007',
'page_title': 'APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, '
'Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, '
'STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, '
'Forest Blizzard, FROZENLAKE, GruesomeLarch, Group '
'G0007 | MITRE ATT&CK®'},
'name': 'APT28',
'type': 'threat-actor'}