Skip to main content
← Threat Intel

Threat Actor

APT28

22 tracked articles · Wikipedia profile

  • CRITICAL 5
  • HIGH 15
  • MEDIUM 2
Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations
HIGH
Threat Intel

Microsoft OWA Exploit: Russian Hackers Bypass Credential Rotations

Russian threat actors exploit a Microsoft Outlook Web Access (OWA) flaw to maintain persistent mailbox access even after passwords are changed or rotated.

Runtime Rebel Intel
4 min read · Jul 30, 2026
TH
HIGH
Threat Intel

APT28 Exploits Exchange OWA Zero-Day to Deploy OWAReaper Backdoor

Russian APT28 hackers exploit an Exchange OWA zero-day to deploy the OWAReaper backdoor, gaining persistent access to high-value government mailboxes.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes
HIGH
Threat Intel

Russian APT Exploits Zimbra Zero-Day to Exfiltrate Mail and 2FA Codes

Russian state-supported actors leveraged a Zimbra Zero-Day to steal 90 days of email history and bypass security by exfiltrating 2FA recovery codes.

Runtime Rebel Intel
3 min read · Jul 23, 2026
TH
CRITICAL
Threat Intel

Zimbra Zero-Click Exploitation by Russian APT for Email Theft

CISA warns of Russian APT Laundry Bear (Void Blizzard) exploiting a patched Zimbra zero-click flaw combined with phishing to compromise email servers for data…

Runtime Rebel Intel
3 min read · Jul 23, 2026
UK and EU Sanction Russian APTs Over Critical Infrastructure Attacks
HIGH
Threat Intel

UK and EU Sanction Russian APTs Over Critical Infrastructure Attacks

Recent UK and EU sanctions target Russian intelligence services following persistent cyber operations against government entities and critical infrastructure.

Runtime Rebel Intel
3 min read · Jul 14, 2026
TH
MEDIUM
Threat Intel

EU Sanctions Russian Intel Officers for APT28 Cyber Operations

The EU imposes sanctions on Russian GRU officers linked to APT28 for long-term cyber espionage and sabotage targeting government and infrastructure.

Runtime Rebel Intel
3 min read · Jul 13, 2026
TH
HIGH
Threat Intel

Russian APTs Target Critical Infrastructure via Edge Device Exploits

US and allies warn of Russian state-sponsored actors targeting edge devices to infiltrate critical infrastructure. Learn how to mitigate these threats.

Runtime Rebel Intel
3 min read · Jul 13, 2026
CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw
HIGH
Threat Intel

CVE-2023-38831: Russian APTs Target Ukraine via WinRAR Flaw

Russian threat actors are exploiting the CVE-2023-38831 WinRAR vulnerability to target Ukrainian government and military entities for data theft.

Runtime Rebel Intel
3 min read · Jun 9, 2026
VU
CRITICAL
Vulnerabilities

APT28 Exploits Incomplete Windows Patch: Zero-Click Attacks Persist

An incomplete Windows patch leaves systems vulnerable to zero-click attacks. Russia-linked APT28 exploited this against Ukraine and EU. Learn how to defend.

Runtime Rebel Intel
4 min read · Apr 27, 2026
APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns
HIGH
Threat Intel

APT28 Analysis: Mitigation Strategies Against Fancy Bear Campaigns

A technical analysis of APT28's global operations, highlighting the necessity of Zero Trust and rapid patching to counter Fancy Bear threat activity.

Runtime Rebel Intel
3 min read · Apr 10, 2026
APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers
CRITICAL
Threat Intel

APT28 Forest Blizzard DNS Manipulation Targets SOHO Routers

Russian APT28, or Forest Blizzard, is conducting malwareless cyber espionage by manipulating DNS settings on vulnerable SOHO routers to steal credentials from global…

Runtime Rebel Intel
5 min read · Apr 9, 2026
APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware
HIGH
Threat Intel

APT28 Targets Ukraine and NATO Allies with New PRISMEX Malware

APT28 (Forest Blizzard) deploys the undocumented PRISMEX malware suite against Ukraine and NATO, utilizing COM hijacking and cloud-based C2 infrastructure.

Runtime Rebel Intel
4 min read · Apr 8, 2026
APT28 Exploits MikroTik & TP-Link Routers in DNS Hijacking
HIGH
Threat Intel

APT28 Exploits MikroTik & TP-Link Routers in DNS Hijacking

Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.

Runtime Rebel Intel
4 min read · Apr 7, 2026
TH
HIGH
Threat Intel

APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins

Authorities disrupt APT28's FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.

Runtime Rebel Intel
5 min read · Apr 7, 2026
TH
HIGH
Threat Intel

Star Blizzard (APT28) Adopts DarkSword iOS Exploit Kit

Russian APT Star Blizzard (APT28) now uses the DarkSword iOS exploit kit to target government, finance, and academia, increasing mobile threat exposure.

Runtime Rebel Intel
5 min read · Mar 30, 2026
TH
HIGH
Threat Intel

APT28 Targets Ukraine via CVE-2024-45519 Zimbra Exploit

Russian APT28 hackers exploit CVE-2024-45519 in Zimbra Collaboration Suite to target Ukrainian government entities via malicious email-based command injection.

Runtime Rebel Intel
3 min read · Mar 19, 2026
TH
HIGH
Threat Intel

Sednit/APT28 Resurfaces: Advanced Toolkit Threat Analysis

Russian-affiliated APT Sednit (APT28) has returned with sophisticated new malware, shifting from simple implants. Understand their updated TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Mar 10, 2026
TH
HIGH
Threat Intel

AI-Enhanced Cyberattacks: Microsoft Details LLM Abuse by APT Groups

Microsoft reveals how nation-state actors like APT28 and Crimson Sandstorm are using AI to automate reconnaissance and refine social engineering lures.

Runtime Rebel Intel
4 min read · Mar 7, 2026
TH
HIGH
Threat Intel

Russian Coruna iOS Exploit Kit Targets Global Users — Analysis

Security researchers uncover the Coruna iOS exploit kit, a nation-state tool now used in broader campaigns to deliver spyware to mobile devices.

Runtime Rebel Intel
4 min read · Mar 5, 2026
APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence
CRITICAL
Threat Intel

APT28 Exploits CVE-2026-21513: MSHTML 0-Day Intelligence

Akamai reports Russia-linked APT28 exploited CVE-2026-21513 in the MSHTML Framework as a zero-day before Microsoft's February 2026 security patch updates.

Runtime Rebel Intel
3 min read · Mar 2, 2026
January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws
CRITICAL
Vulnerabilities

January 2026 CVE Landscape: APT28 Zero-Day & Critical Flaws

Runtime Rebel details January 2026's 23 critical CVEs, including an APT28 zero-day in Microsoft Office and critical enterprise authentication bypass vulnerabilities.

Runtime Rebel Intel
5 min read · Feb 25, 2026
APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe
MEDIUM
Threat Intel

APT28 Operation MacroMaze: Webhook-Driven Macro Execution Targeting Western Europe

Analysis of a targeted campaign attributed to APT28, utilizing macro-enabled documents and legitimate webhook services for command-and-control obfuscation.

Runtime Rebel Intel
3 min read · Feb 24, 2026