APT NOTES

Actor profile · G0007

APT28

A Russian military intelligence-linked intrusion set publicly associated with long-running espionage operations against government, defence, logistics, technology and related targets.

Also tracked as: Fancy Bear · Forest Blizzard · Unit 26165

Actor type
State Sponsored
Status
Active
Suspected origin
Russia
Motivation
Espionage, Credential Access
Active since
2004
Last observed
2025
Confidence
High
Last reviewed
5 Aug 2026
Target regions
Europe, North America
Target sectors
Government, Defence, Logistics, Technology
Reviewer
deividas-lis
Stable ID
apt28

Overview

APT28 is a long-running intrusion set associated in public government and industry reporting with Russia’s military intelligence service. Public naming is not perfectly uniform: labels may describe overlapping, broader or narrower clusters depending on the publisher and collection window.

Attribution

The joint advisory AA25-141A reports that GRU Unit 26165 conducted a campaign against Western logistics and technology organisations involved in coordinating and delivering assistance to Ukraine. APT Notes records that statement as a government attribution claim. It does not independently confirm the underlying classified evidence.

Targeting

Public reporting describes targeting of government, defence, logistics and technology organisations, particularly where their work intersects with Ukraine and Western policy or support networks.

Infrastructure patterns

The 2025 joint advisory describes the use of compromised infrastructure and internet-connected devices alongside credential attacks and exploitation of externally accessible services. These patterns should be treated as campaign context, not immutable actor signatures.

Defensive considerations

Prioritise phishing-resistant authentication, review externally accessible identity and messaging services, monitor password-spraying patterns across accounts, and correlate authentication anomalies with infrastructure and mailbox activity. Do not block solely on an actor label; use behaviour, exposure and corroborated indicators.

Naming and aliases

Vendor tracking clusters may overlap but are not necessarily exact one-to-one equivalents.

AliasSourceRelationshipConfidenceNotes
Fancy BearIndustryCommon AliasHighWidely used public designation; scope may vary by publisher.
Forest BlizzardMicrosoftVendor Tracking ClusterHighMicrosoft tracking name; do not assume exact one-to-one equivalence in every report.
Unit 26165United States governmentGovernment DesignationHighPublic reporting associates the activity with a unit of Russia's GRU.

Source-specific attribution statements

Reported

GRU Unit 26165

A joint government advisory attributes the described logistics and technology campaign to GRU Unit 26165.

Source: CISA AA25-141A · 21 May 2025 · High confidence

This records the source's attribution claim rather than an independent Hecavex confirmation.

MITRE ATT&CK techniques

Sources

  1. Russian GRU Targeting Western Logistics Entities and Technology Companies — CISA, 21 May 2025. Source record
  2. APT28 — Group G0007 — MITRE ATT&CK, 31 May 2017. Source record

Change history

  1. APT28 profile created

    Initial source-backed actor profile added with normalized aliases, attribution and a password-spraying relationship.