APT28, known as Fancy Bear and linked to Russia’s GRU military intelligence, is a long-running group behind political hacking and campaigns against organisations supporting Ukraine.
Key facts
- Attributed to Russia’s GRU military intelligence.
- A May 2025 joint advisory flagged its campaign against Western logistics and IT firms supporting Ukraine.
- History includes political-organisation intrusions and influence operations.
- Uses spear-phishing, credential harvesting and exploitation of known vulnerabilities.
Why it matters
APT28 targets the logistics and IT supply chain behind Western support for Ukraine. Organisations in that ecosystem should monitor closely for exposed credentials.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.