Skip to content

APT28

Russian military cyberespionage group (GRU Unit 26165), tracked as Fancy Bear and BlueDelta, known for phishing campaigns against governments.

Known aliases

  • BlueDelta
  • Fancy Bear
  • Forest Blizzard
  • Military Unit 26165
  • Sofacy
  • STRONTIUM
  • Unidad Militar 26165
  • Unit 26165

Current stories

securityConfirmed4 publishers

Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection

Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence55
Adoption30
Hype gap+25
Incentives
Insufficient
Confidence60
securityConfirmed3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
securityConfirmed3 publishers

Insikt Group traces six months of Word macro lures on three governments to GRU's BlueDelta

The new backdoor, HOOKEDGE, is a Windows batch script that beacons to a free webhook.site endpoint. Insikt Group calls the BlueDelta attribution moderate confidence, resting on overlap with the older HEADLACE implant.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 68%
Investor
Investor 5%

Reality

Evidence60
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence60
securityConfirmed3 publishers

Leaked Bauman files name the GRU department that fed graduates into APT28 and Sandworm

A media consortium and DomainTools worked through more than 2,000 records from a Moscow engineering department that appears on no public org chart, and found roughly 250 students on a documented path into Russian military intelligence.

Perspective Coverage

3 publishers
Builder
Builder 25%
Operator
Operator 65%
Investor
Investor 10%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60