Search Articles — Sudonull

Search Results

From the web

Dec 10, 2025 ·

https://www.picussecurity.com/resource/blog/apt28-cyber-threat-profile-and-detailed-ttps

Dec 10, 2025 · Explore APT28 's history, major campaigns, and MITRE ATT&CK TTPs. Learn how to simulate and defend against this threat with Picus.

Apr 18, 2023 ·

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108

Apr 18, 2023 · APT28 has been known to access vulnerable routers by using default and weak SNMP community strings, and by exploiting CVE-2017-6742 (Cisco Bug ID: CSCve54313) as published by Cisco.

Apr 7, 2026 ·

https://thehackernews.com/2026/04/russian-state-linked-apt28-exploits.html

Apr 7, 2026 · APT28 exploits SOHO routers for global DNS hijacking and adversary-in-the-middle attacks, enabling credential theft and espionage.

Mar 2, 2026 ·

https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html

Mar 2, 2026 · APT28 exploited CVE-2026-21513, an MSHTML zero-day (CVSS 8.8), using malicious LNK files to bypass security controls and execute code.

Alert: I-260407-PSA | 07 APRIL 2026 Russian GRU Exploiting...

https://media.defense.gov/2026/Apr/07/2003907743/-1/-1/0/I-260407-PSA.PDF

Apr 7, 2026 · UNDERSTANDING THE DNS HIJACKING OPERATIONS Since at least 2024, Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors – also known as APT28 , Fancy Bear, and Forest Blizzard – have been collecting credentials and exploiting vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224. The GRU actors changed the devices’ dynamic host ...

Apr 7, 2026 ·

https://www.ncsc.gov.uk/news/apt28-exploit-routers-to-enable-dns-hijacking-operations

Apr 7, 2026 · Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.

Feb 2, 2026 ·

https://www.zscaler.com/blogs/security-research/apt28-leverages-cve-2026-21509-operation-neusploit

Feb 2, 2026 · Zscaler ThreatLabz uncovers APT28 's Operation Neusploit, RTF-based CVE-2026-21509 exploits targeting Central and Eastern Europe.

Feb 4, 2026 ·

https://www.trellix.com/blogs/research/apt28-stealthy-campaign-leveraging-cve-2026-21509-cloud-c2/

Feb 4, 2026 · Russian state-sponsored threat group APT28 (aka Fancy Bear or UAC-0001) has launched a sophisticated espionage campaign targeting European military and government entities, specifically targeting maritime and transport organizations across Poland, Slovenia, Turkey, Greece, the UAE, and Ukraine.

Trending Now