Not part of a guided workflow —
Next best move:Open the platform atlas Atlas

Official ATT&CK groups · sourced comparison

Documented group behavior. Independent vehicle evidence.

Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.

Behavioral overlap is not attributionSIMULATION — NO LIVE ACTIONS
G0007ATT&CK groupLive catalogue

APT28

Also tracked as FROZENLAKE · Fancy Bear · Forest Blizzard · Group 74 · GruesomeLarch · IRON TWILIGHT · Pawn Storm · SNAKEMACKEREL · STRONTIUM · Sednit · Sofacy · Swallowtail · TG-4127 · Threat Group-4127 · Tsar Team

[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citation: FireEye APT28)(Citation: SecureWorks TG-4127)(Citation: FireEye APT28 January 2017)(Citation: GRIZZLY STEPPE JAR)(Citation: Sofacy DealersChoice)(Citation: Palo Alto Sofacy 06-2018)(Citation: Symantec APT28 Oct 2018)(Citation: ESET Zebrocy May 2019) [APT28](https://attack.mitre.org/groups/G0007) reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U.S. presidential election.(Citation: Crowdstrike DNC June 2016) In 2018, the US indicted five GRU Unit 26165 officers associated with [APT28](https://attack.mitre.org/groups/G0007) for cyber operations (including close-access operations) conducted between 2014 and 2018 against the World Anti-Doping Agency (WADA), the US Anti-Doping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations.(Citation: US District Court Indictment GRU Oct 2018) Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as [Sandworm Team](https://attack.mitre.org/groups/G0034).

Attribution boundary

Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.

Official identity source

MITRE ATT&CK · G0007
ATT&CK record
G0007
Record version
5.3
Created
Unknown
Last modified
Unknown
Catalogue release
19.2
Replay fixture
AL-BUILD-TRUST-1.1.0
Technique overlaps
05
Mapped events
07
Evidence gates
14
Defensive analytics
03
Documented groupAPT28T1596

Operational sequence assessment

The active MITRE ATT&CK Enterprise release maps APT28 to T1596 Search Open Technical Databases. Consult the official group record for its cited procedure examples.

Public behavior is a comparison lens · Northstar events below are synthetic · no attribution

Synthetic replay lane · not VIN evidence

Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.

NO VIN

Independent VIN gates

Reached

0/1

Failed gates

0/1

Pending

1/1

Coverage gaps

0/1

0/1 evaluated
  1. 1

Select a VIN to build this group’s full evidence path.

A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.

Select VIN

Exact ATT&CK joins

Public behavior mapped to fixture observations

Full technique playbook

Technique context retained

T1596 is highlighted below. Public group behavior remains separate from synthetic replay evidence.

  1. PATH 01

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps APT28 to T1070.004 Indicator Removal: File Deletion. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E14 to E28

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E1413:00Build interpositionFile integrity

      Workspace restored to the committed state

      The fixture is removed and the workspace again matches the commit. Post-build inspection of the workspace now shows nothing — the window has closed.

      BLD-WIN-03

    2. E1615:00Build interpositionFile integrity

      Short-lived file mutation recorded, not alerted

      File-integrity monitoring recorded create and delete inside the workspace but the workspace path is excluded from alerting. The evidence existed; the rule did not.

      BLD-WIN-03

    3. E2824:30InvestigationFile integrity

      Transient workspace mutation recovered from raw records

      The create/delete pair is still in the raw file-integrity stream even though no alert fired. Retention, not alerting, saved this investigation.

      BLD-WIN-03

  2. PATH 02

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps APT28 to T1071.001 Application Layer Protocol: Web Protocols. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E23 to E23

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E2322:00Downstream signalEgress proxy

      Egress proxy records a first-seen destination from the build tier

      One request to updates.example.net (TEST-NET-2 198.51.100.24) from a host whose baseline destination list contains four entries. First-seen egress from build infrastructure is unusually cheap to detect.

      BLD-WIN-03

  3. PATH 03

    T1078.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps APT28 to T1078.004 Valid Accounts: Cloud Accounts. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E05 to E06

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E0504:00Build accessIdentity

      Build access — an existing automation session is reused

      The scenario grants the emulation a pre-existing automation session on the build tier. How that session was obtained is deliberately out of scope: this exercise studies what happens after trust is already held.

      CI-ORCH-01

    2. E0605:00Build accessIdentity

      Automation identity used outside its schedule

      The automation identity authenticates 43 minutes outside its recorded schedule window. Schedule deviation for non-human identities is a high-value, low-noise signal.

      CI-ORCH-01

  4. PATH 04

    T1591

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps APT28 to T1591 Gather Victim Org Information. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E02 to E02

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E0201:00ReconnaissanceEgress proxy

      Reconnaissance — reasoning about the environment, no intrusion

      The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.

  5. PATH 05

    T1596

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Documented public behavior · MITRE ATT&CK

    The active MITRE ATT&CK Enterprise release maps APT28 to T1596 Search Open Technical Databases. Consult the official group record for its cited procedure examples.

    Historical source context · not replay attribution

    Synthetic replay mapping · E02 to E02

    Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.

    1. E0201:00ReconnaissanceEgress proxy

      Reconnaissance — reasoning about the environment, no intrusion

      The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.