APT28
Russian hacking group targets home and small office routers to spy on users
The FBI, NCSC, and Microsoft warn of an ongoing Russian campaign hijacking DNS settings on home and small office routers to spy on users ...
Response to CISA Advisory (AA25-141A): Russian GRU Targeting Western Logistics Entities and Technology Companies
AttackIQ has released a new assessment template in response to the CISA Advisory (AA25-141A) published on May 21, 2025. The CSA highlights a cyber espionage-oriented campaign carried out by cyber actors affiliated ...
APT28 HeadLace Malware Targeting European Networks Unveiled
In recent months, a series of cyber onslaughts have shaken networks across Europe, with the insidious HeadLace malware at the heart of the storm. This malevolent software, attributed to the Russian GRU-backed ...
Germany Warns Russia: Hacking Will Have Consequences
War of the words: Fancy Bear actions are “intolerable and unacceptable,” complains German foreign minister Annalena Baerbock ...
FBI Warns: Ubiquiti EdgeRouter is STILL Not Secure
GRU APT28 is back again: Fancy Bear still hacking ubiquitous gear, despite patch availability ...
Feds Disrupt Botnet Used by Russian APT28 Hackers
Federal law enforcement kicked Russian state hackers off a botnet comprising at least hundreds of home office and small office routers that had been pulled together by a cybercriminal group and co-opted ...
‘But His Emails!’ — Ukrainian Hackers Hack Hillary Hacker
Beware Fancy Bears Bearing Gifts: Confirms DCLeaks caper was by APT28. Also that APT28 is Russian military unit ...
Did U.S. Charge Klyushin to Reveal 2016 DNC Hack Info?
Vladislav Klyushin is thought to be helping feds learn more about the 2016 DNC breach. But something doesn’t add up ...
Russia, China, Iran Meddle in 2020 Election (Unsurprisingly)
It comes as no surprise to hear that Russia is up to its old tricks. China and Iran are also in on the game ...
Drovorub: Russia Pushing Invisible Malware, say NSA and FBI
Fancy Bear is at it again. This time, it’s said to be infecting Linux machines with Drovorub—rootkit malware that’s very hard to detect ...

