All actors

APT28

Also reported as Sednit, Sofacy, Tsar Team, Forest Blizzard, Swallowtail and 40 other names. Linked to Russia by four sources.

Reports
867
Last reported
Known CVEs
509
Techniques in ATT&CK
93
Origin
Russia
ID
G0007
Merge evidence
84 alias matches

Reports per quarter

  1. 2010 Q1: 1 report
  2. 2010 Q2: 1 report
  3. 2010 Q3: no reports
  4. 2010 Q4: no reports
  5. 2011 Q1: no reports
  6. 2011 Q2: no reports
  7. 2011 Q3: 1 report
  8. 2011 Q4: no reports
  9. 2012 Q1: no reports
  10. 2012 Q2: no reports
  11. 2012 Q3: no reports
  12. 2012 Q4: 4 reports
  13. 2013 Q1: 2 reports
  14. 2013 Q2: no reports
  15. 2013 Q3: 1 report
  16. 2013 Q4: no reports
  17. 2014 Q1: no reports
  18. 2014 Q2: no reports
  19. 2014 Q3: 6 reports
  20. 2014 Q4: 9 reports
  21. 2015 Q1: 8 reports
  22. 2015 Q2: 9 reports
  23. 2015 Q3: 18 reports
  24. 2015 Q4: 20 reports
  25. 2016 Q1: 9 reports
  26. 2016 Q2: 26 reports
  27. 2016 Q3: 23 reports
  28. 2016 Q4: 24 reports
  29. 2017 Q1: 23 reports
  30. 2017 Q2: 11 reports
  31. 2017 Q3: 9 reports
  32. 2017 Q4: 12 reports
  33. 2018 Q1: 18 reports
  34. 2018 Q2: 21 reports
  35. 2018 Q3: 20 reports
  36. 2018 Q4: 29 reports
  37. 2019 Q1: 15 reports
  38. 2019 Q2: 18 reports
  39. 2019 Q3: 15 reports
  40. 2019 Q4: 13 reports
  41. 2020 Q1: 7 reports
  42. 2020 Q2: 13 reports
  43. 2020 Q3: 28 reports
  44. 2020 Q4: 33 reports
  45. 2021 Q1: 10 reports
  46. 2021 Q2: 14 reports
  47. 2021 Q3: 14 reports
  48. 2021 Q4: 11 reports
  49. 2022 Q1: 48 reports
  50. 2022 Q2: 46 reports
  51. 2022 Q3: 20 reports
  52. 2022 Q4: 8 reports
  53. 2023 Q1: 12 reports
  54. 2023 Q2: 14 reports
  55. 2023 Q3: 2 reports
  56. 2023 Q4: 15 reports
  57. 2024 Q1: 12 reports
  58. 2024 Q2: 12 reports
  59. 2024 Q3: 7 reports
  60. 2024 Q4: 6 reports
  61. 2025 Q1: 4 reports
  62. 2025 Q2: 10 reports
  63. 2025 Q3: 9 reports
  64. 2025 Q4: 4 reports
  65. 2026 Q1: 8 reports
  66. 2026 Q2: 129 reports
  67. 2026 Q3: 5 reports
Dated reports, 2010 Q1 to 2026 Q3.

Techniques seen in the last two years

Show all 320 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 509 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Cozy Bear

    date ORKL added it fromORKL

Show all 867 reports Show fewer
  1. Research, News, and Perspectives

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. Research, News, and Perspectives

    date ORKL added it fromORKL

  4. Research, News, and Perspectives

    date ORKL added it fromORKL

  5. Research, News, and Perspectives

    date ORKL added it fromORKL

  6. Research, News, and Perspectives

    date ORKL added it fromORKL

  7. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  8. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  9. Research, News, and Perspectives

    date ORKL added it fromORKL

  10. Olympic Destroyer (Malware Family)

    date ORKL added it fromORKL

  11. Research, News, and Perspectives

    date ORKL added it fromORKL

  12. Research, News, and Perspectives

    date ORKL added it fromORKL

  13. Research, News, and Perspectives

    date ORKL added it fromORKL

  14. Research, News, and Perspectives

    date ORKL added it fromORKL

  15. Research, News, and Perspectives

    date ORKL added it fromORKL

  16. Research, News, and Perspectives

    date ORKL added it fromORKL

  17. Research, News, and Perspectives

    date ORKL added it fromORKL

  18. Research, News, and Perspectives

    date ORKL added it fromORKL

  19. Research, News, and Perspectives

    date ORKL added it fromORKL

  20. Council on Foreign Relations

    date ORKL added it fromORKL

  21. Research, News, and Perspectives

    date ORKL added it fromORKL

  22. Research, News, and Perspectives

    date ORKL added it fromORKL

  23. APT 29, Cozy Bear, The Dukes

    date ORKL added it fromORKL

  24. Research, News, and Perspectives

    date ORKL added it fromORKL

  25. Research, News, and Perspectives

    date ORKL added it fromORKL

  26. Research, News, and Perspectives

    date ORKL added it fromORKL

  27. Research, News, and Perspectives

    date ORKL added it fromORKL

  28. Research, News, and Perspectives

    date ORKL added it fromORKL

  29. Research, News, and Perspectives

    date ORKL added it fromORKL

  30. Research, News, and Perspectives

    date ORKL added it fromORKL

  31. Research, News, and Perspectives

    date ORKL added it fromORKL

  32. Research, News, and Perspectives

    date ORKL added it fromORKL

  33. Research, News, and Perspectives

    date ORKL added it fromORKL

  34. Research, News, and Perspectives

    date ORKL added it fromORKL

  35. Research, News, and Perspectives

    date ORKL added it fromORKL

  36. Research, News, and Perspectives

    date ORKL added it fromORKL

  37. Research, News, and Perspectives

    date ORKL added it fromORKL

  38. Sofacy, APT 28, Fancy Bear, Sednit

    date ORKL added it fromORKL

  39. VPNFilter (Malware Family)

    date ORKL added it fromORKL

  40. Research, News, and Perspectives

    date ORKL added it fromORKL

  41. Research, News, and Perspectives

    date ORKL added it fromORKL

  42. Research, News, and Perspectives

    date ORKL added it fromORKL

  43. Research, News, and Perspectives

    date ORKL added it fromORKL

  44. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  45. Research, News, and Perspectives

    date ORKL added it fromORKL

  46. Research, News, and Perspectives

    date ORKL added it fromORKL

  47. ITG05 leverages malware arsenal

    date ORKL added it fromORKL

  48. CERT-UA

    Malpedia library date fromORKL

  49. CERT-UA

    Malpedia library date fromORKL

  50. CERT-UA

    Malpedia library date fromORKL

  51. CERT-UA

    Malpedia library date fromORKL

  52. CERT-UA

    Malpedia library date fromORKL

  53. New UAC-0050 attack using RemcosRAT

    date in the CCS '25 data CERT-UA fromORKLCCS '25 data

  54. APT29 attacks Embassies using CVE-2023-38831 - report en

    date in the CCS '25 data RSA fromCCS '25 data

  55. CERT-UA

    Malpedia library date fromORKL

  56. CERT-UA

    Malpedia library date fromORKL

  57. Ukraine remains Russia’s biggest cyber focus in 2023

    date in the title fromORKL

  58. Microsoft Security Compliance and Identity

    Malpedia library date Microsoft fromORKL

  59. CERT-UA

    Malpedia library date fromORKL

  60. Detailing Daily Domain Hunting

    date in the title fromORKL

  61. A Deep Dive Into the APT28’s stealer called CredoMap

    date in the title fromORKL

  62. GRU- Rise of the (Telegram) MinIOns

    date in the title fromORKL

  63. The Cluster25 Blog - Duskrise

    Malpedia library date fromORKL

  64. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  65. APT trends report Q2 2020

    date in the title fromORKL

  66. CALISTO continues its credential harvesting campaign

    date in the title fromORKL

  67. Burrowing your way into VPNs, Proxies, and Tunnels

    date in the title fromORKL

  68. Overview of Russian GRU and SVR Cyberespionage Campaigns 1H 2022

    date in the CCS '25 data Bushido Token fromORKLCCS '25 data

  69. Growling Bears Make Thunderous Noise

    date in the title fromORKL

  70. eset_threat_report_t12022

    file creation date fromORKL

  71. Gamaredon Group Understanding the Russian APT

    date in the title fromORKL

  72. GreyEnergys overlap with Zebrocy.pdf

    file creation date fromORKL

  73. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  74. UNC3524: Eye Spy on Your Email

    file creation date Mandiant fromORKL

  75. Update on cyber activity in Eastern Europe

    date in the title fromORKL

  76. UNC3524- Eye Spy on Your Email

    date in the title fromORKL

  77. UNC3524_ Eye Spy on Your Email _ Mandiant

    date in the CCS '25 data Mandiant fromORKLCCS '25 data

  78. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  79. CERT-UA

    Malpedia library date fromORKL

  80. Zebrocy Malware Technical Analysis Report

    date in the title fromORKL

  81. Disrupting cyberattacks targeting Ukraine (APT28)

    date in the title fromORKL

  82. Ukraine CyberWar Overview

    date in the title fromORKL

  83. Threat Thursday- Malicious Macros Still Causing Chaos

    date in the title fromORKL

  84. Who is EMBER BEAR-

    date in the title fromORKL

  85. Sandworm- A tale of disruption told anew

    date in the title fromORKL

  86. Cyclops Blink Sets Sights on Asus Routers

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  87. Cyclops Blink Sets Sights on Asus Routers

    date in the title fromORKL

  88. Threat Update – Ukraine & Russia conflict

    date in the title fromORKL

  89. Shadowserver Special Reports – Cyclops Blink

    date in the title fromORKL

  90. Report2022GTR

    file creation date fromORKL

  91. Threat actor of in-Tur-est

    date in the title fromORKL

  92. Prime Minister’s Office Compromised_ Details of Recent Espionage Campaign

    date in the CCS '25 data Trellix fromORKLCCS '25 data

  93. Anticipating Cyber Threats as the Ukraine Crisis Escalates

    date in the title fromORKL

  94. eset_jumping_the_air_gap_wp

    Malpedia library date ESET fromORKLCCS '25 data

  95. Void Balaur: Tracking a Cybermercenary’s Activities

    Malpedia library date Trend Micro fromORKLCCS '25 data

  96. Technical report Armagedon

    Malpedia library date CrowdStrike fromORKLCCS '25 data

  97. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  98. Countering threats from Iran (APT35)

    date in the title fromORKL

  99. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  100. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  101. The Ghostwriter Scenario (UNC1151)

    date in the title fromORKL

  102. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  103. Ransom DDoS Extortion Actor “Fancy Lazarus” Returns

    date in the title fromORKL

  104. Russian hackers breached Dutch police systems in 2017

    date in the title fromORKL

  105. Another Nobelium Cyberattack

    date in the title fromORKL

  106. Elizabethan England has nothing on modern-day Russia

    date in the title fromORKL

  107. mtrends-2018.pdf

    file creation date fromORKL

  108. 2021-05_FancyBear

    Malpedia library date fromORKL

  109. A Deep Dive into Zebrocy’s Dropper Docs

    date in the title fromORKL

  110. 2021.04.19.A_Deep_Dive_into_Zebrocys_Dropper_Docs

    date in the CCS '25 data SentinelOne fromORKLCCS '25 data

  111. Intezer-2020-Go-Malware-Round-Up.pdf

    Malpedia library date fromORKL

  112. LazyScripter

    Malpedia library date Malwarebytes fromORKLCCS '25 data

  113. The Devil’s in the Details- SUNBURST Attribution

    date in the title fromORKL

  114. Russian cyber attack campaigns and actors

    date in the title fromORKL

  115. Pawn Storm’s Lack of Sophistication as a Strategy

    date in the title fromORKL

  116. Russian APT Uses COVID-19 Lures to Deliver Zebrocy - Intezer

    date in the CCS '25 data Intezer fromORKLCCS '25 data

  117. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  118. Analyzing Network Infrastructure as Composite Objects

    date in the title fromORKL

  119. Cyberattacks targeting health care must stop

    date in the title fromORKL

  120. The CostaRicto Campaign- Cyber-Espionage Outsourced

    date in the title fromORKL

  121. The CostaRicto Campaign_ Cyber-Espionage Outsourced

    date in the CCS '25 data BlackBerry fromORKLCCS '25 data

  122. The Enigmatic Energetic Bear

    date in the title fromORKL

  123. ESET_Threat_Report_Q32020

    file creation date fromORKL

  124. Exploit Developer Spotlight- The Story of PlayBit

    date in the title fromORKL

  125. EU sanctions Russia over 2015 German Parliament hack

    date in the title fromORKL

  126. Revisited- Fancy Bear's New Faces...and Sandworms' too

    date in the title fromORKL

  127. MosaicRegressor- Lurking in the Shadows of UEFI

    date in the title fromORKL

  128. FY20 Microsoft Digital Defense Report

    Malpedia library date fromORKL

  129. APT28 Delivers Zebrocy Malware Campaign Using NATO Theme as Lure

    date in the CCS '25 data QuoIntelligence fromORKLCCS '25 data

  130. New cyberattacks targeting U.S. elections

    date in the title fromORKL

  131. An overview of targeted attacks and APTs on Linux

    date in the title fromORKL

  132. STRONTIUM- Detecting new patterns in credential harvesting

    date in the title fromORKL

  133. Lifting the veil on DeathStalker, a mercenary triumvirate _ Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  134. Lifting the veil on DeathStalker, a mercenary triumvirate

    date in the title fromORKL

  135. Attribution- A Puzzle

    date in the title fromORKL

  136. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  137. ESET_Threat_Report_Q22020

    file creation date fromORKL

  138. APT trends report Q2 2020

    date in the title fromORKL

  139. Russia's GRU Hackers Hit US Government and Energy Targets

    date in the title fromORKL

  140. 游走在东欧和中亚的奇幻熊

    date in the title fromORKL

  141. 0628-2020APT上半年报告-画册

    file creation date fromORKL

  142. Looking at Big Threats Using Code Similarity. Part 1

    date in the title fromORKL

  143. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  144. T1055 Process Injection

    date in the title fromORKL

  145. Bärenjagd

    date in the title fromORKL

  146. ESET_Threat_Report_Q12020

    date in the CCS '25 data ESET fromORKLCCS '25 data

  147. Research, News, and Perspectives

    Malpedia library date fromORKL

  148. APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  149. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  150. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  151. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  152. Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  153. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  154. APT28 Attacks Evolution

    date in the title fromORKL

  155. APT28 Attacks Evolution

    date in the CCS '25 data Marco Ramilli's Blog fromCCS '25 data

  156. Group-IB_Hi-Tech_Crime_Trends_2019-2020

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  157. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  158. Operation Ghost

    Malpedia library date ESET fromORKLCCS '25 data

  159. The-Kittens-Are-Back-in-Town-2

    file creation date fromORKL

  160. Mapping the connections inside Russia APT Ecosystem

    file creation date fromORKL

  161. No summer vacations for Zebrocy

    date in the title fromORKL

  162. Blog | Arctic Wolf

    Malpedia library date Cylance fromORKLCCS '25 data

  163. Inside the APT28 DLL Backdoor Blitz

    date in the title fromORKL

  164. Analytics

    Malpedia library date fromORKL

  165. Operation-Taskmasters-2019-eng

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  166. APT_trends_report_Q2_2019_Securelist

    file creation date fromORKL

  167. Corporate IoT – a path to intrusion (APT28-STRONTIUM)

    date in the title fromORKL

  168. APT trends report Q2 2019

    date in the title fromORKL

  169. Blog | Arctic Wolf

    Malpedia library date Cylance fromORKLCCS '25 data

  170. Flirting With IDA and APT28

    date in the title fromORKL

  171. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  172. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  173. Research, News, and Perspectives

    Malpedia library date fromORKL

  174. Zebrocy Multilanguage Malware Salad

    date in the CCS '25 data EFF fromORKLCCS '25 data

  175. Zebrocy’s Multilanguage Malware Salad

    date in the title fromORKL

  176. One year later- The VPNFilter catastrophe that wasn't

    date in the title fromORKL

  177. A journey to Zebrocy land

    date in the CCS '25 data ESET fromORKLCCS '25 data

  178. A journey to Zebrocy land

    date in the title fromORKL

  179. Malware Against the C Monoculture

    date in the title fromORKL

  180. Research, News, and Perspectives

    Malpedia library date fromORKL

  181. rpt-mtrends-2019.pdf

    file creation date fromORKL

  182. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  183. New steps to protect customers from hacking

    date in the title fromORKL

  184. APT Trends report Q2 2017

    file creation date fromORKL

  185. Cyber Security Report 2019

    date in the CCS '25 data Swisscom fromORKLCCS '25 data

  186. rpt-mtrends-2019

    file creation date fromORKL

  187. 2018 APT Summary Report CN version

    file creation date fromORKL

  188. 2018 Master Table

    file creation date fromORKL

  189. GreyEnergy’s overlap with Zebrocy

    date in the title fromORKL

  190. ENISA Threat Landscape Report 2018

    file creation date fromORKL

  191. A Zebrocy Go Downloader

    date in the title fromORKL

  192. Let's Learn In-Depth on APT28Sofacy Zebrocy Golang Loader

    date in the CCS '25 data Blog fromCCS '25 data

  193. Sofacy Creates New ‘Go’ Variant of Zebrocy Tool

    date in the title fromORKL

  194. Dear Joohn- The Sofacy Group’s Global Campaign

    date in the title fromORKL

  195. Snakemackerel delivers Zekapab malware

    date in the title fromORKL

  196. Sednit- What’s going on with Zebrocy-

    date in the title fromORKL

  197. CozyBear – In from the Cold-

    date in the title fromORKL

  198. Octopus-infested seas of Central Asia

    date in the title fromORKL

  199. Russian-language actor exploits hype over Telegram ban in Central Asia

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  200. Cobalt Group 2.0

    date in the title fromORKL

  201. Indicators of Compromise for Malware used by APT28

    date in the title fromORKL

  202. APT28 Uses LoJax, First UEFI Rootkit Seen in the Wild

    date in the title fromORKL

  203. ESET-LoJax

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  204. Silence: Moving into the darkside

    date in the CCS '25 data Group-IB fromORKLCCS '25 data

  205. HITB-SG-2018-E - In the trails of WINDSHIFT [Autosaved]

    date in the CCS '25 data Bellingcat fromORKLCCS '25 data

  206. Remember Fancy Bear-

    date in the title fromORKL

  207. Microsoft claims win over 'Russian political hackers'

    date in the title fromORKL

  208. 20180713_CSE_APT28_X-Agent_Op-Roman Holiday-Report_v6_1

    date in the CCS '25 data Pierluigi Paganini fromORKLCCS '25 data

  209. APT Trends Report Q2 2018

    date in the title fromORKL

  210. adobe-flash-zero-day-targeted-attack

    date in the CCS '25 data ICEBRG fromORKLCCS '25 data

  211. Sofacy Group’s Parallel Attacks - Palo Alto Networks Blog

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  212. Sofacy Group’s Parallel Attacks

    date in the title fromORKL

  213. APT28 Rollercoaster- The Lowdown on Hijacked Lo

    date in the title fromORKL

  214. VPNFilter EXIF to C2 mechanism analysed

    date in the title fromORKL

  215. Russian hackers posed as IS to threaten military wives

    date in the title fromORKL

  216. Who's who in the Zoo - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  217. Lojack Becomes a Double-Agent

    date in the title fromORKL

  218. Lojack Becomes a Double-Agent | NETSCOUT

    Malpedia library date fromORKL

  219. M-TRENDS2018

    file creation date FireEye fromORKL

  220. Zebrocy used heavily by the Sednit group over last two years

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  221. Sednit update- Analysis of Zebrocy

    date in the title fromORKL

  222. APT Trends report Q1 2018

    date in the title fromORKL

  223. Masha and these Bears - 2018 Sofacy Activity

    date in the title fromORKL

  224. masha-and-these-bears

    date in the CCS '25 data RSA fromORKLCCS '25 data

  225. OlympicDestroyer is here to trick the industry

    date in the title fromORKL

  226. OlympicDestroyer is here to trick the industry - Securelist

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  227. Sofacy Attacks Multiple Government Entities

    file creation date fromORKL

  228. ukatemicrysys_territorialdispute

    Malpedia library date fromORKL

  229. Sofacy Attacks Multiple Government Entities

    date in the title fromORKL

  230. A Slice of 2017 Sofacy Activity

    date in the title fromORKL

  231. A Slice of 2017 Sofacy Activity - Securelist

    date in the CCS '25 data NATO fromORKLCCS '25 data

  232. Update on Pawn Storm: New Targets and Politically Motivated Campaigns

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  233. Sednit update- How Fancy Bear Spent the Year

    date in the title fromORKL

  234. Research, News, and Perspectives

    Malpedia library date fromORKL

  235. Advanced Persistent Threat Groups

    date in the title fromORKL

  236. Threat Group APT28 Slips Office Malware into Doc Citing NYC Terror Attack

    date in the CCS '25 data McAfee fromORKLCCS '25 data

  237. russian-federation-country-profile.pdf

    Malpedia library date fromORKL

  238. Introducing WhiteBear - Securelist

    file creation date fromORKL

  239. Cyber Conflict Decoy Document Used In Real Cyber Conflict

    date in the CCS '25 data Cisco fromORKLCCS '25 data

  240. Introducing WhiteBear

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  241. Introducing WhiteBear

    date in the title fromORKL

  242. Analysis of APT28 hospitality malware (Part 2)

    date in the title fromORKL

  243. Research, News, and Perspectives

    Malpedia library date fromORKL

  244. Threat Group-4127 Targets Google Accounts | Secureworks

    date in the CCS '25 data Google fromORKLCCS '25 data

  245. The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  246. Open Source Malware - Sharing is caring?

    Malpedia library date fromORKL

  247. Open Source Malware - Sharing is caring-

    date in the title fromORKL

  248. TAINTED LEAKS Disinformation and Phishing With a Russian Nexus

    date in the CCS '25 data Citizen Lab fromORKLCCS '25 data

  249. Snake- Coming soon in Mac OS X flavour

    date in the title fromORKL

  250. Research, News, and Perspectives

    Malpedia library date fromORKL

  251. Update on the Fancy Bear Android malware (poprd30.apk)

    date in the title fromORKL

  252. The Deception Project: A New Japanese-Centric Threat

    date in the CCS '25 data Cylance fromORKLCCS '25 data

  253. The Deception Project- A New Japanese-Centric Threat

    date in the title fromORKL

  254. Threat Group-4127 Targets Google Accounts

    file creation date Secureworks fromORKL

  255. XAgentOSX- Sofacy’s XAgent macOS Tool

    date in the title fromORKL

  256. Enhanced Analysis of GRIZZLY STEPPE Activity

    file creation date US-CERT fromORKL

  257. [tr1adx]_ Intel

    date in the CCS '25 data tr1adx fromORKLCCS '25 data

  258. Mac Malware of 2016

    date in the title fromORKL

  259. GRIZZLY STEPPE - Russian Malicious Cyber Activity

    date in the CCS '25 data US-CERT fromORKLCCS '25 data

  260. Bear Hunting Season: Tracking APT28

    date in the CCS '25 data tr1adx fromORKLCCS '25 data

  261. Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units

    date in the CCS '25 data Crowdstrike fromORKLCCS '25 data

  262. Russia Hacks Bellingcat MH17 Investigation _ ThreatConnect

    file creation date fromORKL

  263. Research, News, and Perspectives

    Malpedia library date fromORKL

  264. Let It Ride: The Sofacy Group's DealersChoice Attacks Continue

    date in the CCS '25 data Palo Alto Networks fromORKLCCS '25 data

  265. Microsoft_Security_Intelligence_Report_Volume_21_English

    file creation date fromORKL

  266. En Route with Sednit Part 2: Observing the Comings and Goings

    date in the CCS '25 data ESET fromCCS '25 data

  267. En Route with Sednit Part 2: Observing the Comings and Goings

    Malpedia library date ESET fromORKL

  268. En Route with Sednit Part 1: Approaching the Target

    date in the CCS '25 data ESET fromCCS '25 data

  269. Belling the BEAR

    file creation date ThreatConnect fromORKL

  270. Sofacy's Komplex OS X Trojan

    file creation date Palo Alto fromORKL

  271. How France's TV5 was almost destroyed by 'Russian hackers'

    date in the title fromORKL

  272. Research, News, and Perspectives

    Malpedia library date fromORKL

  273. Belling the BEAR

    date in the title fromORKL

  274. Komplex Mac backdoor answers old questions

    date in the title fromORKL

  275. Sofacy’s ‘Komplex’ OS X Trojan

    date in the title fromORKL

  276. Hackers lurking, parliamentarians told

    date in the title fromORKL

  277. Research, News, and Perspectives

    Malpedia library date fromORKL

  278. Research, News, and Perspectives

    Malpedia library date fromORKL

  279. En Route with Sednit Part 3: A Mysterious Downloader

    Malpedia library date ESET fromORKL

  280. Bartholomew-GuerreroSaade-VB2016.indd

    Malpedia library date Kaspersky fromORKL

  281. Research, News, and Perspectives

    Malpedia library date fromORKL

  282. Russian_Cyber_Operations_On_Steroids

    date in the CCS '25 data ThreatConnect fromORKLCCS '25 data

  283. Running for Office_ Russian APT Toolkits Revealed

    file creation date fromORKL

  284. En Route with Sednit Part 1: Approaching the Target

    Malpedia library date ESET fromORKL

  285. Please Read

    date in the CCS '25 data FireEye and Microsoft fromORKLCCS '25 data

  286. Research, News, and Perspectives

    Malpedia library date fromORKL

  287. Findings from Analysis of DNC Intrusion Malware

    file creation date Fidelis fromORKL

  288. Research, News, and Perspectives

    Malpedia library date fromORKL

  289. Visiting The Bear Den A Journey in the Land of (Cyber-)Espionage

    date in the CCS '25 data ESET fromCCS '25 data

  290. Threat Group-4127 Targets Hillary Clinton Presidential Campaign

    date in the CCS '25 data Secureworks fromORKLCCS '25 data

  291. PowerPoint Presentation

    file creation date ESET fromORKL

  292. New Sofacy Attacks Against US Government Agency

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  293. New Sofacy Attacks Against US Government Agency

    date in the title fromORKL

  294. Bears in the Midst: Intrusion into the Democratic National Committee

    date in the CCS '25 data Crowdstrike fromORKLCCS '25 data

  295. Research, News, and Perspectives

    Malpedia library date fromORKL

  296. Stealth Falcon

    date in the CCS '25 data Citizen Lab fromORKLCCS '25 data

  297. Research, News, and Perspectives

    Malpedia library date fromORKL

  298. Research, News, and Perspectives

    Malpedia library date fromORKL

  299. ib-entertainment.pdf

    file creation date fromORKL

  300. Looking Into a Cyber-Attack Facilitator in the Netherlands

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  301. Looking Into a Cyber-Attack Facilitator in the Netherlands (Appendix)

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  302. A Look Into Fysbis: Sofacy's Linux Backdoor

    file creation date Palo Alto fromORKL

  303. A Look Into Fysbis- Sofacy’s Linux Backdoor

    date in the title fromORKL

  304. 2015年中国高持续性威胁(APT)研究报告

    file creation date fromORKL

  305. Sofacy APT hits high profile targets with updated toolset

    date in the title fromORKL

  306. Research, News, and Perspectives

    Malpedia library date fromORKL

  307. Introducing LogPOS

    date in the title fromORKL

  308. Microsoft Security Intelligence Report (Volume 19)

    date in the CCS '25 data Microsoft fromCCS '25 data

  309. rpt-witchcoven

    Malpedia library date FireEye fromORKLCCS '25 data

  310. Research, News, and Perspectives

    Malpedia library date fromORKL

  311. Pawn Storm Targets MH17 Investigation Team

    date in the title fromORKL

  312. Research, News, and Perspectives

    Malpedia library date fromORKL

  313. Research, News, and Perspectives

    Malpedia library date fromORKL

  314. Research, News, and Perspectives

    Malpedia library date fromORKL

  315. The Dukes: 7 years of Russian cyberespionage

    file creation date F-Secure fromORKL

  316. Research, News, and Perspectives

    Malpedia library date fromORKL

  317. Fancy Bear

    date in the title fromORKL

  318. Fancy Bear

    Malpedia library date fromORKL

  319. Fancy Bear

    Malpedia library date fromORKL

  320. New Spear Phishing Campaign Pretends to be EFF

    date in the title fromORKL

  321. Islamic State Hacking Division

    date in the title fromORKL

  322. Islamic State Hacking Division

    Malpedia library date fromORKL

  323. HTExploitTelemetry

    Malpedia library date FireEye fromORKLCCS '25 data

  324. An In-Depth Look at How Pawn Storm’s Java Zero-Day Was Used

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  325. Sednit APT Group Meets Hacking Team

    date in the title fromORKL

  326. R9b_FSOFACY_0

    date in the CCS '25 data root9B fromORKLCCS '25 data

  327. APT28 Targets Financial Markets: Zero Day Hashes Released

    file creation date root9b fromORKL

  328. APT28 Targets Financial Markets

    date in the CCS '25 data root9b fromCCS '25 data

  329. Sofacy II_ Same Sofacy, Different Day

    file creation date PWC fromORKL

  330. Research, News, and Perspectives

    Malpedia library date fromORKL

  331. Research, News, and Perspectives

    Malpedia library date fromORKL

  332. Research, News, and Perspectives

    Malpedia library date fromORKL

  333. rpt-m-trends-2015.pdf

    file creation date fromORKL

  334. Research, News, and Perspectives

    Malpedia library date fromORKL

  335. Global Threat Intel Report

    Malpedia library date Crowdstrike fromORKL

  336. Pawn Storm Update- iOS Espionage App Found

    date in the title fromORKL

  337. Pawn Storm Update: iOS Espionage App Found

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  338. Research, News, and Perspectives

    Malpedia library date fromORKL

  339. Research, News, and Perspectives

    Malpedia library date fromORKL

  340. Research, News, and Perspectives

    Malpedia library date fromORKL

  341. apt28

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  342. APT28 Report | FireEye

    file creation date fromORKL

  343. Operation Pawn Storm: Using Decoys to Evade Detection

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  344. Tactical Intelligence Bulletin Sofacy Phishing

    date in the CCS '25 data PWC fromORKLCCS '25 data

  345. OPERATION QUANTUM ENTANGLEMENT

    Malpedia library date fromORKL

  346. Research, News, and Perspectives

    Malpedia library date fromORKL

  347. Research, News, and Perspectives

    Malpedia library date fromORKL

  348. Research, News, and Perspectives

    Malpedia library date fromORKL

  349. Research, News, and Perspectives

    Malpedia library date fromORKL

  350. Research, News, and Perspectives

    Malpedia library date fromORKL

  351. Research, News, and Perspectives

    Malpedia library date fromORKL

  352. Research, News, and Perspectives

    Malpedia library date fromORKL

  353. Research, News, and Perspectives

    Malpedia library date fromORKL

  354. Research, News, and Perspectives

    Malpedia library date fromORKL

  355. Research, News, and Perspectives

    Malpedia library date fromORKL

  356. Research, News, and Perspectives

    Malpedia library date fromORKL

  357. Research, News, and Perspectives

    Malpedia library date fromORKL

  358. Research, News, and Perspectives

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.