Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
APT28
Also tracked as FROZENLAKE · Fancy Bear · Forest Blizzard · Group 74 · GruesomeLarch · IRON TWILIGHT · Pawn Storm · SNAKEMACKEREL · STRONTIUM · Sednit · Sofacy · Swallowtail · TG-4127 · Threat Group-4127 · Tsar Team
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0007- ATT&CK record
- G0007
- Record version
- 5.3
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 05
- Mapped events
- 07
- Evidence gates
- 14
- Defensive analytics
- 03
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps APT28 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/3
Failed gates
0/3
Pending
3/3
Coverage gaps
0/3
- 1
- 2
- 3
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1070.004 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1070.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT28 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E14 to E28
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E1413:00Build interpositionFile integrity
Workspace restored to the committed state
The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.
BLD-WIN-03
- E1615:00Build interpositionFile integrity
Short-lived file mutation recorded, not alerted
File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.
BLD-WIN-03
- E2824:30InvestigationFile integrity
Transient workspace mutation recovered from raw records
The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.
BLD-WIN-03
PATH 02
T1071.001
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT28 to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E23 to E23
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E2322:00Downstream signalEgress proxy
Egress proxy records a first-seen destination from the build tier
One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.
BLD-WIN-03
PATH 03
T1078.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT28 to T1078.004 Valid Accounts: Cloud Accounts. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E05 to E06
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0504:00Build accessIdentity
Build access — an existing automation session is reused
The scenario grants the emulation a pre-existing automation session on the build tier. How that session was obtained is deliberately out of scope: this exercise studies what happens after trust is already held.
CI-ORCH-01
- E0605:00Build accessIdentity
Automation identity used outside its schedule
The automation identity authenticates 43 minutes outside its recorded schedule window. Schedule deviation for non-human identities is a high-value, low-noise signal.
CI-ORCH-01
PATH 04
T1591
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT28 to T1591 Gather Victim Org Information. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E02 to E02
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0201:00ReconnaissanceEgress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.
PATH 05
T1596
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps APT28 to T1596 Search Open Technical Databases. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E02 to E02
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0201:00ReconnaissanceEgress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.