Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0007
MITRE ATT&CK Group

APT28 (G0007)

IRON TWILIGHTSNAKEMACKERELSwallowtailGroup 74SednitSofacyPawn StormFancy BearSTRONTIUMTsar TeamThreat Group-4127TG-4127Forest BlizzardFROZENLAKEGruesomeLarch
ShareXLinkedInRedditHN

[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).

▪Techniques used (93)

T1003.003NTDST1589.001CredentialsT1591Gather Victim Org InformationT1564.001Hidden Files and DirectoriesT1583.003Virtual Private ServerT1596Search Open Technical DatabasesT1583.001DomainsT1070.006TimestompT1090.002External ProxyT1566.001Spearphishing AttachmentT1059.001PowerShellT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1547.001Registry Run Keys / Startup FolderT1027.013Encrypted/Encoded FileT1203Exploitation for Client ExecutionT1586.002Email AccountsT1114.002Remote Email CollectionT1505.003Web ShellT1584.008Network DevicesT1550.002Pass the HashT1037.001Logon Script (Windows)T1588.002ToolT1564.003Hidden WindowT1090.003Multi-hop ProxyT1567Exfiltration Over Web ServiceT1056.001KeyloggingT1083File and Directory DiscoveryT1190Exploit Public-Facing ApplicationT1669Wi-Fi NetworksT1039Data from Network Shared DriveT1113Screen CaptureT1110.001Password GuessingT1583.006Web ServicesT1057Process DiscoveryT1189Drive-by CompromiseT1595.002Vulnerability ScanningT1546.015Component Object Model HijackingT1199Trusted RelationshipT1120Peripheral Device DiscoveryT1059.003Windows Command ShellT1557.004Evil TwinT1498Network Denial of ServiceT1070.004File DeletionT1560Archive Collected DataT1105Ingress Tool TransferT1598Phishing for InformationT1559.002Dynamic Data ExchangeT1036.005Match Legitimate Resource Name or LocationT1119Automated CollectionT1078.004Cloud AccountsT1221Template InjectionT1005Data from Local SystemT1213.002SharepointT1078Valid AccountsT1025Data from Removable MediaT1071.001Web ProtocolsT1213Data from Information RepositoriesT1218.011Rundll32T1560.001Archive via UtilityT1140Deobfuscate/Decode Files or InformationT1598.003Spearphishing LinkT1542.003BootkitT1071.003Mail ProtocolsT1036MasqueradingT1210Exploitation of Remote ServicesT1014RootkitT1204.002Malicious FileT1550.001Application Access TokenT1030Data Transfer Size LimitsT1134.001Token Impersonation/TheftT1074.002Remote Data StagingT1092Communication Through Removable MediaT1098.002Additional Email Delegate PermissionsT1003OS Credential DumpingT1040Network SniffingT1068Exploitation for Privilege EscalationT1137.002Office TestT1528Steal Application Access TokenT1110.003Password SprayingT1204.001Malicious LinkT1133External Remote ServicesT1102.002Bidirectional CommunicationT1001.001Junk DataT1685.005Clear Windows Event LogsT1211Exploitation for StealthT1003.001LSASS MemoryT1573.001Symmetric CryptographyT1074.001Local Data StagingT1091Replication Through Removable MediaT1588.007Artificial IntelligenceT1110Brute ForceT1684.001ImpersonationT1021.002SMB/Windows Admin Shares

▪Software used (30)

S0645WevtutiltoolS0160certutiltoolS0023CHOPSTICKmalwareS0039NettoolS0193ForfilestoolS0243DealersChoicemalwareS0002MimikatztoolS0045ADVSTORESHELLmalwareS0351CannonmalwareS0162KomplexmalwareS0135HIDEDRVmalwareS0044JHUHUGITmalwareS0250KoadictoolS0191WinexetoolS0174RespondertoolS1205cipher.exetoolS0117XTunnelmalwareS0502DrovorubmalwareS9035LAMEHUGmalwareS0183TortoolS0137CORESHELLmalwareS0138OLDBAITmalwareS0134DowndelphmalwareS0161XAgentOSXmalwareS0136USBStealermalwareS0251ZebrocymalwareS1187reGeorgmalwareS0410FysbismalwareS0397LoJaxmalwareS0314X-Agent for Androidmalware
G0007on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.