Actor profile · G0007
APT28
A Russian military intelligence-linked intrusion set publicly associated with long-running espionage operations against government, defence, logistics, technology and related targets.
Also tracked as: Fancy Bear · Forest Blizzard · Unit 26165
- Actor type
- State Sponsored
- Status
- Active
- Suspected origin
- Russia
- Motivation
- Espionage, Credential Access
- Active since
- 2004
- Last observed
- 2025
- Confidence
- High
- Last reviewed
- 5 Aug 2026
- Target regions
- Europe, North America
- Target sectors
- Government, Defence, Logistics, Technology
- Reviewer
- deividas-lis
- Stable ID
- apt28
Overview
APT28 is a long-running intrusion set associated in public government and industry reporting with Russia’s military intelligence service. Public naming is not perfectly uniform: labels may describe overlapping, broader or narrower clusters depending on the publisher and collection window.
Attribution
The joint advisory AA25-141A reports that GRU Unit 26165 conducted a campaign against Western logistics and technology organisations involved in coordinating and delivering assistance to Ukraine. APT Notes records that statement as a government attribution claim. It does not independently confirm the underlying classified evidence.
Targeting
Public reporting describes targeting of government, defence, logistics and technology organisations, particularly where their work intersects with Ukraine and Western policy or support networks.
Infrastructure patterns
The 2025 joint advisory describes the use of compromised infrastructure and internet-connected devices alongside credential attacks and exploitation of externally accessible services. These patterns should be treated as campaign context, not immutable actor signatures.
Defensive considerations
Prioritise phishing-resistant authentication, review externally accessible identity and messaging services, monitor password-spraying patterns across accounts, and correlate authentication anomalies with infrastructure and mailbox activity. Do not block solely on an actor label; use behaviour, exposure and corroborated indicators.
Naming and aliases
Vendor tracking clusters may overlap but are not necessarily exact one-to-one equivalents.
| Alias | Source | Relationship | Confidence | Notes |
|---|---|---|---|---|
| Fancy Bear | Industry | Common Alias | High | Widely used public designation; scope may vary by publisher. |
| Forest Blizzard | Microsoft | Vendor Tracking Cluster | High | Microsoft tracking name; do not assume exact one-to-one equivalence in every report. |
| Unit 26165 | United States government | Government Designation | High | Public reporting associates the activity with a unit of Russia's GRU. |
Source-specific attribution statements
GRU Unit 26165
A joint government advisory attributes the described logistics and technology campaign to GRU Unit 26165.
This records the source's attribution claim rather than an independent Hecavex confirmation.
MITRE ATT&CK techniques
Sources
- Russian GRU Targeting Western Logistics Entities and Technology Companies — CISA, 21 May 2025. Source record
- APT28 — Group G0007 — MITRE ATT&CK, 31 May 2017. Source record
Change history
APT28 profile created
Initial source-backed actor profile added with normalized aliases, attribution and a password-spraying relationship.