Adversary-emulation profile for APT28 (G0007 / Fancy Bear / Forest Blizzard / Sofacy / STRONTIUM), Russia's GRU Unit 26165 cyber-espionage actor.
54
61%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/apt28-fancy-bear/SKILL.mdAPT28 (MITRE ATT&CK G0007) is a long-running cyber-espionage group attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS), military unit 26165, operating since at least 2004. Across two decades it has hit governments, militaries, diplomatic bodies, defense and aerospace, anti-doping and chemical-weapons watchdogs, media, and — since 2022 — Western logistics and IT firms supporting Ukraine. APT28 is best characterized by disciplined credential operations (spearphishing, large-scale password spraying, NTLM-coercion), pragmatic use of N-day exploits (Outlook, Exchange, WinRAR, Windows Print Spooler), a broad cross-platform malware stable (Windows/Linux/macOS/Android, plus the LoJax UEFI rootkit), and a willingness to pivot from pure espionage into influence, hack-and-leak, and occasional destructive/DDoS operations. This profile maps its tradecraft to ATT&CK so Decepticon can emulate it inside an authorized engagement and the blue cell can anticipate detection.
UserInitMprLogonScript.-WindowStyle Hidden), NTFS attribute hiding (LoJax).reg save, NTDS via ntdsutil/VSS, LSA secrets, DCSync (Mimikatz).Compress-Archive.C:\ProgramData, pi.log) and remote staging on OWA server.netsh portproxy) and multi-hop proxy (Tor/VPN).cipher.exe.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| CHOPSTICK / X-Agent | S0023 | Modular Windows implant (DGA, fileless) | Custom |
| JHUHUGIT / Seduploader | S0044 | First-stage Windows implant | Custom |
| ADVSTORESHELL | S0045 | Backdoor with custom archiving | Custom |
| XTunnel | S0117 | Network proxy/tunnel | Custom |
| CORESHELL / Sofacy | S0137 | Windows downloader/backdoor | Custom |
| Downdelph | S0134 | Delphi backdoor + bootkit | Custom |
| LoJax | S0397 | UEFI rootkit (firmware persistence) | Custom |
| Drovorub | S0502 | Linux malware suite + kernel rootkit | Custom |
| Fysbis | S0410 | Linux backdoor | Custom |
| Komplex / XAgentOSX | S0162 / S0161 | macOS trojan / implant | Custom |
| X-Agent for Android | S0314 | Android surveillance | Custom |
| Zebrocy | S0251 | Multi-stage downloader/collector | Custom |
| Cannon | S0351 | Backdoor with email-based exfil | Custom |
| OLDBAIT | S0138 | Credential stealer | Custom |
| USBStealer | S0136 | USB/air-gap exfil | Custom |
| GooseEgg | (no ATT&CK software ID assigned) | Print Spooler privesc launcher (CVE-2022-38028) | Custom |
| LAMEHUG | S9035 | LLM-assisted post-compromise implant | Custom |
| reGeorg | S1187 | Web shell / SOCKS tunnel | Public (Living-off-tooling) |
| Koadic | S0250 | Post-exploitation framework | Public |
| Mimikatz | S0002 | Credential dumping | Public |
| Responder | S0174 | LLMNR/NBT-NS poisoning | Public |
| Tor | S0183 | Anonymity / proxy | Public |
| Net / netsh / certutil / Wevtutil / Forfiles | S0039 / S0108 / S0160 / S0645 / S0193 | LOLBins | Built-in |
Note: "GooseEgg" is a Microsoft-attributed custom tool; it is not the same as ATT&CK software S1145 (Pikabot), so no false software ID is assigned here.
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run destructive (T1561/T1498) or firmware (LoJax-style) actions outside an explicitly sanctioned, isolated lab.
Map APT28's signature plays to Decepticon's own capabilities:
netsh portproxy internal proxies + reGeorg-style web-shell tunneling for pivoting.Compress-Archive, split into <1MB chunks, and exfil over HTTPS through a compromised OWA-equivalent or a web service to reproduce the signature exfil pattern.PidLidReminderFileParameter UNC paths; alert on outbound NTLM to external hosts.spoolsv.exe spawning cmd/PowerShell and writes to Spooler driver/JS-constraints paths.ntdsutil/vssadmin shadow-copy creation, and reg save of SAM/SYSTEM/SECURITY; monitor DCSync replication from non-DC accounts.Add-MailboxPermission/ApplicationImpersonation role grants; restrict user consent; review delegate/forwarding rules.netsh interface portproxy add; baseline web-server child processes.UserInitMprLogonScript, Office Test registry keys; deploy Secure Boot + firmware integrity (against LoJax-class UEFI implants).4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.