If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/groups/G0007 - APT28, IRON TWILIGHT, SNAKEMAC.

site address: attack.mitre.org/groups/G0007 redirected to: attack.mitre.org/groups/G0007

site title: APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, Group G0007 MITRE ATT&CK®

Our opinion (on Friday 28 August 2026 8:46:15 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


page from cache: 1 hour ago
Meta tags:

Headings (most frequently used words):

apt28, associated, group, descriptions, campaigns, techniques, used, software, references, enterprise, layer,

Text of the page (most frequently used words):
apt28 (156), and (98), the (95), #enterprise (85), has (76), discovery (75), retrieved (60), data (59), used (58), system (56), information (39), execution (37), for (34), files (32), file (32), command (32), windows (31), from (31), protocol (30), web (29), 2017 (28), network (28), credentials (27), access (26), application (26), 2018 (25), group (25), campaign (25), proxy (25), layer (23), threat (22), november (22), account (22), 001 (22), nearest (21), neighbor (21), with (20), credential (20), local (20), password (20), protocols (20), service (20), remote (20), tool (19), process (19), channel (19), encrypted (19), scripting (19), services (19), during (19), interpreter (18), logon (18), 2016 (17), microsoft (17), security (17), over (17), boot (17), 002 (17), registry (16), collected (16), 2015 (15), user (15), obfuscated (15), transfer (15), shell (15), february (14), sofacy (14), using (14), removal (14), directory (14), exfiltration (14), archive (14), cryptography (13), autostart (13), modify (13), also (13), software (12), october (12), 2024 (12), july (12), capture (12), indicator (12), name (12), compromised (12), email (12), victim (12), that (12), att (11), groups (11), attacks (11), december (11), office (11), malicious (11), target (11), ingress (11), encoding (11), legitimate (11), via (11), powershell (11), 003 (11), use (10), all (10), tools (10), march (10), 2020 (10), staged (10), startup (10), through (10), domain (10), including (10), cve (10), intelligence (9), malware (9), into (9), april (9), 2019 (9), authentication (9), august (9), phishing (9), compromise (9), deletion (9), run (9), keys (9), masquerading (9), server (9), dumping (9), rundll32 (9), exe (9), team (8), september (8), storm (8), google (8), uses (8), networks (8), brute (8), force (8), asymmetric (8), decode (8), folder (8), collection (8), mail (8), location (8), event (8), removable (8), media (8), communication (8), injection (8), accounts (8), global (7), falcone (7), gru (7), pawn (7), sednit (7), persistence (7), attack (7), june (7), 2022 (7), 4127 (7), configuration (7), scheduled (7), task (7), device (7), staging (7), stores (7), junk (7), disable (7), usb (7), smb (7), dll (7), spearphishing (7), utility (7), binary (7), wipe (7), documents (7), conducted (7), techniques (6), russia (6), trojan (6), operations (6), open (6), rootkit (6), targets (6), infrastructure (6), unit (6), cyber (6), owner (6), screen (6), storage (6), input (6), deobfuscate (6), script (6), keylogging (6), match (6), encoded (6), firewall (6), create (6), token (6), against (6), symmetric (6), exploitation (6), internal (6), disk (6), custom (6), devices (6), commands (6), version (6), victims (6), its (6), 2026 (5), ics (5), mobile (5), none (5), domains (5), campaigns (5), fancy (5), bear (5), 2023 (5), agency (5), lee (5), russian (5), eset (5), first (5), lamehug (5), government (5), volume (5), targeted (5), iron (5), twilight (5), time (5), standard (5), scripts (5), automated (5), code (5), resource (5), component (5), shares (5), manipulation (5), steal (5), manager (5), hide (5), artifacts (5), hidden (5), ntds (5), drive (5), dccc (5), emails (5), payload (5), large (5), other (5), deployed (5), can (5), gather (5), associated (5), mitre (4), 2025 (4), hacquebord (4), may (4), research (4), route (4), part (4), test (4), january (4), new (4), 2021 (4), strontium (4), snakemackerel (4), active (4), they (4), query (4), peripheral (4), share (4), browsers (4), channels (4), admin (4), desktop (4), triggered (4), pass (4), alternate (4), material (4), tickets (4), mimikatz (4), dynamic (4), link (4), control (4), object (4), hijacking (4), chopstick (4), initial (4), exploited (4), gain (4), such (4), users (4), within (4), several (4), applications (4), stage (4), loader (4), owa (4), inserted (4), servers (4), have (4), both (4), publicly (4), available (4), obtain (4), capabilities (4), conduct (4), public (4), spray (4), per (4), compress (4), been (4), registered (3), resources (3), cti (3), detection (3), defenses (3), backdoor (3), two (3), lojax (3), actors (3), multiple (3), scanning (3), fireeye (3), leveraged (3), how (3), center (3), harvesting (3), analysis (3), activity (3), secureworks (3), espionage (3), military (3), organizations (3), window (3), democratic (3), committee (3), deploys (3), references (3), management (3), instrumentation (3), connections (3), job (3), api (3), initialization (3), fallback (3), native (3), logs (3), wevtutil (3), replication (3), hop (3), tor (3), poisoning (3), relay (3), responder (3), non (3), netsh (3), permission (3), additional (3), ticket (3), hash (3), forge (3), lsass (3), memory (3), bypass (3), mechanism (3), koadic (3), privilege (3), escalation (3), model (3), jhuhugit (3), forfiles (3), content (3), cipher (3), 004 (3), get (3), containing (3), macro (3), lateral (3), movement (3), dnc (3), word (3), execute (3), protection (3), sent (3), when (3), traffic (3), their (3), external (3), systems (3), bootkit (3), reg (3), save (3), hklm (3), which (3), algorithm (3), captured (3), distributed (3), anti (3), doping (3), exfiltrated (3), winrar (3), exchange (3), performed (3), computer (3), variety (3), attempts (3), vulnerability (3), websites (3), facing (3), cmd (3), created (3), cmdlet (3), spraying (3), scale (3), acquire (3), gruesomelarch (3), frozenlake (3), forest (3), blizzard (3), tsar (3), this (3), swallowtail (3), corporation (2), are (2), policy (2), terms (2), contact (2), reference (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), android (2), tracking (2), ukrainian (2), paganini (2), linked (2), entities (2), robert (2), komplex (2), fysbis (2), department (2), officers (2), social (2), engineering (2), xagentosx (2), uefi (2), found (2), known (2), llm (2), links (2), technical (2), method (2), dde (2), digital (2), report (2), cannon (2), elections (2), high (2), profile (2), exploits (2), likely (2), apt (2), weaponized (2), ukraine (2), corporate (2), iot (2), intrusion (2), kaspersky (2), lab (2), downloader (2), conflict (2), ctu (2), indictment (2), united (2), states (2), zebrocy (2), dealerschoice (2), hillary (2), clinton (2), presidential (2), national (2), will (2), nsa (2), fbi (2), cloud (2), environments (2), 85th (2), gtsss (2), previously (2), drovorub (2), unsecured (2), insertion (2), agent (2), clear (2), log (2), timestomp (2), multi (2), sniffing (2), resolution (2), adversary (2), middle (2), python (2), regeorg (2), helper (2), net (2), private (2), kerberos (2), controller (2), history (2), firmware (2), pre (2), attributes (2), bidirectional (2), attachment (2), trust (2), directories (2), library (2), clipboard (2), abuse (2), elevation (2), unix (2), extensions (2), obfuscation (2), downdelph (2), client (2), certutil (2), wireless (2), organization (2), environment (2), administrator (2), privileges (2), collect (2), maintain (2), exfiltrate (2), login (2), passwords (2), attachments (2), oauth (2), tokens (2), gmail (2), yahoo (2), template (2), function (2), executed (2), saved (2), batch (2), impersonation (2), modified (2), outlook (2), language (2), models (2), llms (2), search (2), connected (2), itself (2), air (2), gapped (2), computers (2), infected (2), drives (2), vpn (2), proxies (2), instance (2), nato (2), allow (2), communications (2), between (2), built (2), current (2), permissions (2), some (2), redirect (2), module (2), dumped (2), dit (2), shadow (2), copies (2), vssadmin (2), dump (2), sam (2), regularly (2), retrieval (2), key (2), hkcu (2), special (2), source (2), payloads (2), base64 (2), close (2), denial (2), world (2), appear (2), renamed (2), 005 (2), executing (2), perform (2), implant (2), 006 (2), deleted (2), about (2), 2014 (2), 1701 (2), vulnerable (2), exploit (2), archives (2), https (2), webpages (2), added (2), set (2), host (2), direct (2), contents (2), each (2), was (2), shared (2), sharepoint (2), various (2), repositories (2), tooling (2), operated (2), modes (2), mode (2), hour (2), course (2), days (2), kubernetes (2), cluster (2), guessing (2), implants (2), later (2), evil (2), twin (2), attempt (2), last (2), seen (2), designation (2), reporting (2), refer (2), g0007 (2), 26165 (2), main (2), ckcon (2), person (2), faq (2), trademarks, cookie, preferences, website, changelog, privacy, reset, filters, sub, crowdstrike, field, artillery, units, france, anssi, warns, french, dani, creus, tyler, halfpop, bryan, rob, downs, look, linux, justice, charges, international, hacking, related, influence, disinformation, years, examining, increasingly, relevant, dear, joohn, abuses, advanced, xagent, macos, wild, courtesy, simonovich, cato, ctrl, analyzing, powered, observing, comings, goings, walkthrough, recent, gtig, tracker, advances, actor, usage, observed, deliver, sherstobitoff, rea, slips, doc, citing, nyc, terror, openai, disrupting, state, affiliated, staying, ahead, age, bulletin, ms17, 010, critical, smith, read, hospitality, sector, presents, travelers, bitdefender, under, scope, approaching, guarnieri, german, parliament, investigative, hack, left, party, bundestag, maccaglia, evolving, threats, dissection, cyberespionage, anthe, continues, wheels, out, burt, cyberattacks, targeting, playbook, viewer, year, huntley, update, landscape, labs, operation, russiandoll, adobe, zero, day, highly, koessel, sean, adair, steven, lancaster, tom, nearby, covert, billy, leonard, remains, biggest, focus, names, mstic, detecting, patterns, msrc, path, slice, remorin, lack, sophistication, strategy, mysterious, hits, updated, toolset, mercer, decoy, document, real, accenture, supports, measures, brady, aleksei, sergeyevich, morenets, journey, land, symantec, response, parallel, european, homeland, federal, bureau, investigation, grizzly, steppe, isight, counter, alperovitch, bears, midst, gallagher, did, try, again, hackers, mueller, america, viktor, borisovich, netyksho, cisa, ncsc, conducting, undisclosed, packing, hooking, s0251, xtunnel, s0117, s0161, s0314, winexe, s0191, s0645, physical, medium, usbstealer, s0136, s0183, s0174, ssh, tunneling, s1187, oldbait, s0138, s0108, connection, s0039, silver, golden, certificates, rogue, dcsync, lsa, secrets, support, provider, sid, s0002, ntfs, s0397, s9035, launch, s0162, regsvr32, mshta, visual, basic, s0250, s0044, hidedrv, s0135, masquerade, systemd, xdg, entries, s0410, indirect, s0193, kernel, modules, s0502, hijack, flow, s0134, s0243, coreshell, s0137, s1205, virtualization, sandbox, evasion, fileless, generation, algorithms, s0023, install, root, certificate, subvert, controls, s0160, winlogon, s0351, advstoreshell, s0045, established, secure, belonging, points, t1669, t1102, 365, inboxes, specifically, stolen, default, manufacturer, voip, phone, printer, video, decoder, valid, t1078, attempted, click, tricked, unwitting, recipients, clicking, hyperlinks, crafted, resemble, trustworthy, senders, t1204, abused, t1550, once, gained, then, proceeded, trusted, relationship, t1199, abusing, retrieve, t1221, interfaces, range, t1016, dropper, twain_64, 011, t1218, defender, scanner, delivery, mcafee, t1528, impersonating, officials, t1684, t1505, assist, development, deployment, databases, t1596, take, screenshots, t1113, unified, extensible, interface, t1014, infect, transmit, t1091, move, laterally, mapped, rdp, t1021, routed, obfuscate, activities, georgian, point, acts, even, behind, router, machine, obscure, portproxy, t1090, enumerate, processes, searching, explorer, does, not, necessary, t1057, along, ensure, variants, blackenergy, t1542, sites, t1598, rar, t1566, receive, notification, every, mass, t1120, creating, ntdsutil, export, database, following, hives, minidump, t1003, adding, perf, t1137, generate, return, post, artificial, 007, obtained, like, t1588, rtl, encryption, xor, rc4, 013, t1027, netbios, usernames, hashed, allowed, teams, pineapples, intercept, signals, t1040, ddos, t1498, changed, make, them, benign, page, avoid, t1036, delivered, inter, t1559, t1056, downloaded, second, t1105, timestomping, intentionally, cover, tracks, program, ccleaner, t1070, windowstyle, parameter, conceal, t1564, satellite, org, t1591, harvested, identity, t1589, locate, pdf, excel, searched, specific, t1083, commercial, t1133, t1210, 4902, features, stealth, t1211, 4076, 2387, 0263, 38028, escalate, t1068, 0262, t1203, 0688, 17144, sql, t1190, webservers, t1567, alternative, t1048, com, replacing, mmdeviceenumerator, 015, t1546, installed, delphi, t1573, t1114, strategic, utilizing, kits, reflected, cross, site, xss, t1189, securely, folders, overwriting, t1561, cleared, t1685, rules, series, port, forwards, allowing, t1686, accessed, order, t1006, unarchived, gui, txt, storing, t1140, split, archived, chunks, smaller, than, 1mb, size, limits, t1030, programdata, stored, named, t1074, string, preventing, trivial, decoding, without, knowledge, given, length, value, tracked, seamless, but, prevent, wire, t1001, entire, t1025, t1039, machines, inside, before, t1005, t1213, ubiquiti, act, 008, t1584, send, t1586, captures, transfers, t1092, macros, among, functions, childitem, downloads, executes, performs, t1059, validate, approximately, four, weeks, typically, 300, hours, t1110, adds, establish, userinitmprlogonscript, t1037, copied, t1547, t1119, utilities, t1560, imap, pop3, smtp, self, blend, http, depending, t1071, pineapple, purposes, capturing, planting, oriented, t1557, scans, find, t1595, newly, blogspot, pages, hosted, free, brief, periods, virtual, imitating, osce, caucasus, t1583, grant, role, applicationimpersonation, delegate, t1098, copy, theft, t1134, view, download, navigator, layers, early, c0051, description, descriptions, live, permalink, drew, church, splunk, emily, ratliff, ibm, richard, gold, shadows, sébastien, ruel, cgi, contributors, reportedly, congressional, interfere, election, indicted, five, wada, nuclear, facility, prohibition, chemical, weapons, opcw, spiez, swiss, chemicals, laboratory, these, were, assistance, 74455, referred, sandworm, attributed, general, staff, directorate, since, least, 2004, home, join, mclean, hotel, details, register, here, blog, contribute, benefactors, legal, branding, updates, engage, advisory, council, learn, more, started, detections,


Text of the page (random words):
ents before exfiltration 36 3 30 2 enterprise t1039 data from network shared drive apt28 has collected files from network shared drives 2 enterprise t1025 data from removable media an apt28 backdoor may collect the entire contents of an inserted usb device 34 enterprise t1001 001 data obfuscation junk data apt28 added junk data to each encoded string preventing trivial decoding without knowledge of the junk removal algorithm each implant was given a junk length value when created tracked by the controller software to allow seamless communication but prevent analysis of the command protocol on the wire 6 enterprise t1074 001 data staged local data staging apt28 has stored captured credential information in a file named pi log 34 during apt28 nearest neighbor campaign apt28 staged captured credential information in the c programdata directory 27 002 data staged remote data staging apt28 has staged archives of collected data on a target s outlook web access owa server 2 enterprise t1030 data transfer size limits apt28 has split archived exfiltration files into chunks smaller than 1mb 2 enterprise t1140 deobfuscate decode files or information an apt28 macro uses the command certutil decode to decode contents of a txt file storing the base64 encoded payload 37 11 during apt28 nearest neighbor campaign apt28 unarchived data using the gui version of winrar 27 enterprise t1006 direct volume access during apt28 nearest neighbor campaign apt28 accessed volume shadow copies through executing vssadmin in order to dump the ntds dit file 27 enterprise t1686 003 disable or modify system firewall windows host firewall during apt28 nearest neighbor campaign apt28 added rules to a victim s windows firewall to set up a series of port forwards allowing traffic to target systems 27 enterprise t1685 005 disable or modify tools clear windows event logs apt28 has cleared event logs including by using the commands wevtutil cl system and wevtutil cl security 5 3 enterprise t1561 001 disk wipe disk content wipe during apt28 nearest neighbor campaign apt28 used the native microsoft utility cipher exe to securely wipe files and folders overwriting the deleted data using cmd exe c cipher w c 27 enterprise t1189 drive by compromise apt28 has compromised targets via strategic web compromise utilizing custom exploit kits 16 apt28 used reflected cross site scripting xss against government websites to redirect users to phishing webpages 26 enterprise t1114 002 email collection remote email collection apt28 has collected emails from victim microsoft exchange servers 3 2 enterprise t1573 001 encrypted channel symmetric cryptography apt28 installed a delphi backdoor that used a custom algorithm for c2 communications 13 enterprise t1546 015 event triggered execution component object model hijacking apt28 has used com hijacking for persistence by replacing the legitimate mmdeviceenumerator object with a payload 38 13 enterprise t1048 002 exfiltration over alternative protocol exfiltration over asymmetric encrypted non c2 protocol apt28 has exfiltrated archives of collected data previously staged on a target s owa server via https 2 enterprise t1567 exfiltration over web service apt28 can exfiltrate data over google drive 21 during apt28 nearest neighbor campaign apt28 exfiltrated data over public facing webservers such as google drive 27 enterprise t1190 exploit public facing application apt28 has used a variety of public exploits including cve 2020 0688 and cve 2020 17144 to gain execution on vulnerable microsoft exchange they have also conducted sql injection attacks against external websites 14 2 enterprise t1203 exploitation for client execution apt28 has exploited microsoft office vulnerability cve 2017 0262 for execution 22 enterprise t1068 exploitation for privilege escalation apt28 has exploited cve 2014 4076 cve 2015 2387 cve 2015 1701 cve 2017 0263 and cve 2022 38028 to escalate privileges 39 34 22 27 enterprise t1211 exploitation for stealth apt28 has used cve 2015 4902 to bypass security features 39 34 enterprise t1210 exploitation of remote services apt28 exploited a windows smb remote code execution vulnerability to conduct lateral movement 6 40 41 enterprise t1133 external remote services apt28 has used tor and a variety of commercial vpn services to route brute force authentication attempts 2 enterprise t1083 file and directory discovery apt28 has used forfiles to locate pdf excel and word documents during collection the group also searched a compromised dccc computer for specific terms 36 3 enterprise t1589 001 gather victim identity information credentials apt28 has harvested user s login credentials 32 enterprise t1591 gather victim org information apt28 has used large language models llms to gather information about satellite capabilities 42 43 enterprise t1564 001 hide artifacts hidden files and directories apt28 has saved files with hidden file attributes 18 18 003 hide artifacts hidden window apt28 has used the windowstyle parameter to conceal powershell windows 11 44 enterprise t1070 004 indicator removal file deletion apt28 has intentionally deleted computer files to cover their tracks including with use of the program ccleaner 3 006 indicator removal timestomp apt28 has performed timestomping on victim files 5 enterprise t1105 ingress tool transfer apt28 has downloaded additional files including by using a first stage downloader to contact the c2 server to obtain the second stage implant 39 31 17 21 2 enterprise t1056 001 input capture keylogging apt28 has used tools to perform keylogging 34 3 21 enterprise t1559 002 inter process communication dynamic data exchange apt28 has delivered jhuhugit and koadic by executing powershell commands through dde in word documents 44 45 11 enterprise t1036 masquerading apt28 has renamed the winrar utility to avoid detection 2 005 match legitimate resource name or location apt28 has changed extensions on files containing exfiltrated data to make them appear benign and renamed a web shell instance to appear as a legitimate owa page 2 enterprise t1498 network denial of service in 2016 apt28 conducted a distributed denial of service ddos attack against the world anti doping agency 14 enterprise t1040 network sniffing apt28 deployed the open source tool responder to conduct netbios name service poisoning which captured usernames and hashed passwords that allowed access to legitimate credentials 6 40 apt28 close access teams have used wi fi pineapples to intercept wi fi signals and user credentials 14 enterprise t1027 013 obfuscated files or information encrypted encoded file apt28 encrypted a dll payload using rtl and a custom encryption algorithm apt28 has also obfuscated payloads with base64 xor and rc4 39 37 11 18 17 enterprise t1588 002 obtain capabilities tool apt28 has obtained and used open source tools like koadic mimikatz and responder 11 22 40 007 obtain capabilities artificial intelligence apt28 has deployed lamehug which can can query an llm to generate and return commands for post compromise activity on targeted systems 46 enterprise t1137 002 office application startup office test apt28 has used the office test persistence mechanism within microsoft office by adding the registry key hkcu software microsoft office test special perf to execute code 47 enterprise t1003 os credential dumping apt28 regularly deploys both publicly available ex mimikatz and custom password retrieval tools on victims 48 3 14 001 lsass memory apt28 regularly deploys both publicly available ex mimikatz and custom password retrieval tools on victims 48 3 they have also dumped the lsass process memory using the minidump function 2 002 security account manager during apt28 nearest neighbor campaign apt28 used the following commands to dump sam system and security hives reg save hklm sam reg save hklm system and reg save hklm security 27 003 ntds apt28 has used the ntdsutil exe utility to export the active directory database for credential access 2 during apt28 nearest neighbor campaign apt28 dumped ntds dit through creating volume shadow copies via vssadmin 27 enterprise t1120 peripheral device discovery apt28 uses a module to receive a notification every time a usb mass storage device is inserted into a victim 34 enterprise t1566 001 phishing spearphishing attachment apt28 sent spearphishing emails containing malicious microsoft office and rar attachments 37 10 11 3 22 17 21 16 49 enterprise t1598 phishing for information apt28 has used spearphishing to compromise credentials 32 16 003 spearphishing link apt28 has conducted credential phishing campaigns with links that redirect to credential harvesting sites 29 3 13 14 16 enterprise t1542 003 pre os boot bootkit apt28 has deployed a bootkit along with downdelph to ensure its persistence on the victim the bootkit shares code with some variants of blackenergy 20 enterprise t1057 process discovery an apt28 loader trojan will enumerate the victim s processes searching for explorer exe if its current process does not have necessary permissions 31 enterprise t1090 001 proxy internal proxy during apt28 nearest neighbor campaign apt28 used the built in netsh portproxy command to create internal proxies on compromised systems 27 002 proxy external proxy apt28 used other victims as proxies to relay command traffic for instance using a compromised georgian military email server as a hop point to nato victims the group has also used a tool that acts as a proxy to allow c2 even if the victim is behind a router apt28 has also used a machine to relay and obscure communications between chopstick and their server 6 39 3 003 proxy multi hop proxy apt28 has routed traffic over tor and vpn servers to obfuscate their activities 21 enterprise t1021 001 remote services remote desktop protocol during apt28 nearest neighbor campaign apt28 used rdp for lateral movement 27 002 remote services smb windows admin shares apt28 has mapped network drives using net and administrator credentials 2 during apt28 nearest neighbor campaign apt28 leveraged smb to transfer files and move laterally 27 enterprise t1091 replication through removable media apt28 uses a tool to infect connected usb devices and transmit itself to air gapped computers when the infected usb device is inserted 34 enterprise t1014 rootkit apt28 has used a uefi unified extensible firmware interface rootkit known as lojax 12 50 enterprise t1113 screen capture apt28 has used tools to take screenshots from victims 48 51 3 16 enterprise t1596 search open technical databases apt28 has used large language models llms to assist in script development and deployment 42 43 enterprise t1505 003 server software component web shell apt28 has used a modified and obfuscated version of the regeorg web shell to maintain persistence on a target s outlook web access owa server 2 enterprise t1684 001 social engineering impersonation lamehug has sent spearphishing emails impersonating ukrainian government officials 49 enterprise t1528 steal application access token apt28 has used several malicious applications to steal user oauth access tokens including applications masquerading as google defender google email protection and google scanner for gmail users they also targeted yahoo users with applications masquerading as delivery service and mcafee email protection 52 enterprise t1218 011 system binary proxy execution rundll32 apt28 executed chopstick by using rundll32 commands such as rundll32 exe c windows twain_64 dll apt28 also executed a dll for a first stage dropper using rundll32 exe an apt28 loader trojan saved a batch script that uses rundll32 to execute a dll payload 5 39 11 31 13 2 enterprise t1016 002 system network configuration discovery wi fi discovery during apt28 nearest neighbor campaign apt28 collected information on wireless interfaces within range of a compromised system 27 enterprise t1221 template injection apt28 used weaponized microsoft word documents abusing the remote template function to retrieve a malicious macro 53 enterprise t1199 trusted relationship once apt28 gained access to the dccc network the group then proceeded to use that access to compromise the dnc network 3 enterprise t1550 001 use alternate authentication material application access token apt28 has used several malicious applications that abused oauth access tokens to gain access to target email accounts including gmail and yahoo mail 52 002 use alternate authentication material pass the hash apt28 has used pass the hash for lateral movement 34 enterprise t1204 001 user execution malicious link apt28 has tricked unwitting recipients into clicking on malicious hyperlinks within emails crafted to resemble trustworthy senders 14 16 002 user execution malicious file apt28 attempted to get users to click on microsoft office attachments containing malicious macro scripts 37 17 16 49 enterprise t1078 valid accounts apt28 has used legitimate credentials to gain initial access maintain access and exfiltrate data from a victim network the group has specifically used credentials stolen through a spearphishing email to login to the dccc network the group has also leveraged default manufacturer s passwords to gain initial access to corporate networks via iot devices such as a voip phone printer and video decoder 54 3 23 2 004 cloud accounts apt28 has used compromised office 365 service accounts with global administrator privileges to collect email from user inboxes 2 enterprise t1102 002 web service bidirectional communication apt28 has used google drive for c2 21 enterprise t1669 wi fi networks apt28 has exploited open wi fi access points for initial access to target devices using the network 27 55 during apt28 nearest neighbor campaign apt28 established wireless connections to secure enterprise wi fi networks belonging to a target organization for initial access into the environment 27 software id name references techniques s0045 advstoreshell 19 22 application layer protocol web protocols archive collected data archive collected data archive via custom method boot or logon autostart execution registry run keys startup folder command and scripting interpreter windows command shell data encoding standard encoding data staged local data staging encrypted channel symmetric cryptography encrypted channel asymmetric cryptography event triggered execution component object model hijacking exfiltration over c2 channel file and directory discovery indicator removal file deletion input capture keylogging modify registry native api obfuscated files or information peripheral device discovery process discovery query registry scheduled transfer system binary proxy execution rundll32 system information discovery s0351 cannon 33 53 application layer protocol mail protocols boot or logon autostart execution winlogon helper dll exfiltration over c2 channel file and directory discovery ingress tool transfer local storage discovery process discovery screen capture system information d...
Images from subpage: "attack.mitre.org/techniques/T1059" Verify
Images from subpage: "attack.mitre.org/techniques/T1059/001" Verify
Images from subpage: "attack.mitre.org/techniques/T1059/003" Verify
Images from subpage: "attack.mitre.org/techniques/T1584" Verify
Images from subpage: "attack.mitre.org/techniques/T1074" Verify

Verified site has: 255 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-210 211-215 216-220 221-225 226-230 231-235 236-240 241-245 246-250
251-255


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/groups/G0007
X-GitHub-Request-Id BA56:61B8F:25D30B3:262AAAE:6A913B54
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Fri, 28 Aug 2026 07:40:05 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290050-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787902805.237717,VS0,VE108
Vary Accept-Encoding
X-Fastly-Request-ID 2bbe8b4ea42cea0097d543ad70ba7bed00bd8859
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/groups/G0007/
access-control-allow-origin *
expires Fri, 28 Aug 2026 07:50:05 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id B13C:99576:4324B1:46B4AF:6A913B54
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Fri, 28 Aug 2026 07:40:05 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630021-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787902805.372919,VS0,VE84
vary Accept-Encoding
x-fastly-request-id ffad2202ba1882be469ff2300030f2370d6cdf66
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:04 GMT
access-control-allow-origin *
etag W/ 6a75ea84-57608
expires Fri, 28 Aug 2026 07:50:05 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id BA2C:99576:4324B4:46B4B6:6A913B55
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Fri, 28 Aug 2026 07:40:05 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630021-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787902805.464360,VS0,VE89
vary Accept-Encoding
x-fastly-request-id 562beac89797b77d50db6b740e9bfbb635689fdc
content-length 45567

Meta Tags

title="APT28, IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch, Group G0007 | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size357896
load time (s)0.605762
redirect count2
speed download75317
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"