All Posts
Cyber Threat Intelligence
Malware
Research
ThreatStream
1
min read

A Timeline of APT28 Activity

Published on
February 22, 2018
Table of Contents
<p><strong>APT28</strong> (aka Fancy Bear, aka Pawn Storm, aka Sednit, aka Sofacy, aka Group 74, aka Sednit, aka Sofacy, aka Strontium, aka Threat Group-4127) finds its way into the news with some regularity. Most recently the group claimed to have released documents from the International Luge Federation. APT28 is probably best known for its attacks on the Democratic National Committee (DNC) and other political targets in 2016. The group has a reputation for being organized and stealthy in their campaigns. Their choice of targets often aligns with Russian geopolitical interests.</p><p>Below is an image that summarizes publicly known APT28 activity from 2014 to present:</p><p style="text-align: center;"><img alt="" src="https://cdn.filestackcontent.com/ietdH7dbRVSf05YW6MLD"/></p><p style="text-align: center;"><em>Summary of APT28 Malicious Activity</em></p><p>Activities from APT28 have been covered by a number of information security research teams since first being reported on by Trend Micro in 2014. This corpus of information on the group is spread amongst a number of sources. The Anomali Labs team has compiled a timeline of all publicly known APT28 activities and shared it in this informative <a href="https://forum.anomali.com/t/apt28-timeline-of-malicious-activity/2019" target="_blank">post in the </a><a href="https://forum.anomali.com/t/apt28-timeline-of-malicious-activity/2019" target="_blank">Anomali</a><a href="https://forum.anomali.com/t/apt28-timeline-of-malicious-activity/2019" target="_blank"> Forum</a>.</p>

FEATURED RESOURCES

August 11, 2026
Operationalized Threat Intelligence
Agentic SOC

OCSF, Explained: Why a Common Schema Changes How Security Teams Work

How a vendor-neutral schema turns fragmented telemetry into data your analysts, detections, and AI agents can all read.
Read More
August 11, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Your AI Clicked Something, Your Dev Tools Have Worms, and the Hotel Wi-Fi Was Literally a Spy

Midnight Blizzard's CaptiveCrunch Campaign Turns Hotel Wi-Fi Into an Espionage Tool. AI Cyber Testing Incidents Multiply as Frontier Models Reach Real Systems and People. ChainDrop Worm Turns Developer Tools Into a Self-Spreading Supply Chain Threat. N-able N-central Authentication Bypass Under Active Exploitation. DOUBLECUP ClickFix Loader-as-a-Service Delivers CountLoader and DeviceManager RATs. Zero-Click Indirect Prompt Injection Attacks Target AI Agentic Browsers, Enabling Account Takeover and Unauthorized Actions.
Read More
August 4, 2026
Anomali Cyber Watch

Anomali Cyber Watch: TA488 Exploits OWA Cross-Site Scripting, Certighost Domains Hijack, TELESHIM Abuses Telegram, and more

TA488 Exploits OWA Cross-Site Scripting Flaw to Deploy OWAReaper JavaScript Implant, New Certighost PoC Exploit Lets Attackers Hijack Windows Domains, TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments, Chinese-Speaking Threat Actor Deploys Autonomous AI-Driven Attack Campaign, Nested Trust: HollowFrame's Layered Loader and Matryoshka Backdoors, Custom Backdoor Toolkit Targets Central Asian Government Networks in Cyber-Espionage Campaign
Read More
Explore All