NATO and the EU formally condemned APT28 cyber espionageSecurity Affairs·May 12, 16:39 UTC · May 12, 2024Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
Why the DNC hackers will continue to wreak havocCyberScoop·Jan 17, 23:06 UTC · Jan 17, 2017Exploit / PoC in the wild60
APT28 group is rushing to exploit recent CVE-2017-11292 Flash 0Security Affairs·Oct 22, 11:29 UTC · Oct 22, 2017VulnerabilityCVE-2017-11292CVE-2015-7645CVE-2016-1019+2 CVEs60
APT28 exploits Microsoft Office flaw in Operation NeusploitSecurity Affairs·Feb 3, 12:13 UTC · Feb 3, 2026Threat actor in the wildCVE-2026-2150960
France links Russian APT28 to attacks on dozen French entitiesSecurity Affairs·Apr 30, 13:58 UTC · Apr 30, 2025Threat actorCVE-2023-2339760
Russia-linked APT28 compromised Ubiquiti EdgeRouters to facilitate cyber operationsSecurity Affairs·Feb 28, 11:43 UTC · Feb 28, 2024Threat actorCVE-2021-36260CVE-2022-46169CVE-2021-35394+1 CVEs160
Russia-linked APT28 targets government Polish institutionsSecurity Affairs·May 10, 11:07 UTC · May 10, 2024Threat actorCVE-2023-2339760
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office ZeroRecorded Future·Feb 24, 00:00 UTC · Feb 24, 2026Vulnerability in the wildCVE-2026-21509CVE-2026-23760CVE-2026-1281+1 CVEs160
APT28 targeted Montenegro's government before it joined NATO, researchers sayCyberScoop·Jun 6, 22:12 UTC · Jun 6, 2017Threat actor in the wild60
Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accountsSecurity Affairs·Dec 5, 14:19 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-40444+4 CVEs60
Microsoft disrupted APT28 attacks on Ukraine through a court orderSecurity Affairs·Apr 8, 09:44 UTC · Apr 8, 2022Threat actor60
Researchers link Macron hack to APT28 with 'moderate confidence'CyberScoop·May 11, 15:01 UTC · May 11, 2017Threat actor in the wild60
Russia-linked APT28 exploited MSHTML zero-day CVE-2026Security Affairs·Mar 2, 14:46 UTC · Mar 2, 2026Exploit / PoCCVE-2026-2151360
Chinese Threat Actor TEMP.Periscope Targets UK-Based Engineering Company Using Russian APT TechniquesRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Threat actor60
Microsoft Outlook Flaw Exploited by Russia's APT28 to Hack Czech, German EntitiesThe Hacker News·May 9, 05:20 UTC · May 9, 2024Threat actorCVE-2023-23397CVE-2022-3802860
APT28 has been scanning vulnerable email servers in the last yearSecurity Affairs·Mar 20, 12:47 UTC · Mar 20, 2020Threat actor60
Report: APT28 breached German foreign and defense ministriesCyberScoop·Mar 1, 03:36 UTC · Mar 1, 2018Data breach in the wild60
APT28 hacking crew plans attacks on financial institutionsSecurity Affairs·May 15, 22:06 UTC · May 15, 2015Threat actor60
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking CampaignThe Hacker News·Apr 8, 16:11 UTC · Apr 8, 2026Threat actorCVE-2023-50224160
Cybersecurity Agencies Warn Ubiquiti EdgeRouter Users of APT28's MooBot ThreatThe Hacker News·Feb 28, 12:55 UTC · Feb 28, 2024Threat actorCVE-2023-2339760
US Thwarts DNS Hijacking Network Controlled by Russian APT28 HackersInfosecurity Magazine·Apr 8, 10:03 UTC · Apr 8, 2026Threat actor60
France Slams Russia’s APT28 for Four-Year CyberInfosecurity Magazine·Apr 30, 09:45 UTC · Apr 30, 2025Threat actor60
Russian APT28 Exploits Outlook Bug to Access ExchangeInfosecurity Magazine·Dec 5, 10:40 UTC · Dec 5, 2023Threat actorCVE-2023-23397CVE-2023-38831CVE-2021-4044460
APT28 hacked Roundcube email servers of Ukrainian entitiesSecurity Affairs·Jun 21, 19:20 UTC · Jun 21, 2023Threat actorCVE-2020-35730CVE-2020-12641CVE-2021-44026+1 CVEs60
APT28-linked trojan being developed in multiple programming languages, research showsCyberScoop·Dec 18, 22:59 UTC · Dec 18, 2018Malware in the wild160
Lawmakers call for action following revelations that APT28 posed as ISIS onlineCyberScoop·May 9, 19:44 UTC · May 9, 2018Threat actor in the wild60
Russia's APT8 exploited Outlook 0day to target EU NATO membersSecurity Affairs·Dec 8, 00:07 UTC · Dec 8, 2023Threat actorCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
ANSSI warns of RussiaSecurity Affairs·Oct 27, 13:34 UTC · Oct 27, 2023Data breachCVE-2023-23397CVE-2022-30190CVE-2020-12641+2 CVEs60
Russia-linked hackers impersonate NATO in attempt to hack Romanian governmentCyberScoop·May 11, 14:16 UTC · May 11, 2017Exploit / PoC in the wild60
Russia-linked APT28 uses PRISMEX to infiltrate Ukraine and allied infrastructure with advanced tacticsSecurity Affairs·Apr 8, 20:23 UTC · Apr 8, 2026Threat actorCVE-2026-21509CVE-2026-2151360
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch TuesdayThe Hacker News·Mar 2, 10:36 UTC · Mar 2, 2026VulnerabilityCVE-2026-21513CVE-2026-21509160
Kremlin-Backed APT28 Targets Polish Institutions in LargeThe Hacker News·May 10, 09:55 UTC · May 10, 2024Threat actor60
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO AlliesThe Hacker News·Apr 8, 13:50 UTC · Apr 8, 2026MalwareCVE-2026-21509CVE-2026-2151360
Russia-Linked APT28 Exploited MDaemon ZeroThe Hacker News·May 15, 00:00 UTC · May 15, 2025Threat actor in the wildCVE-2020-12641CVE-2020-35730CVE-2021-44026+3 CVEs60
APT28 targets key networks in Europe with HeadLace malwareSecurity Affairs·Jun 3, 09:55 UTC · Jun 3, 2024Malware55
APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing SchemeThe Hacker News·Mar 19, 13:33 UTC · Mar 19, 2024Threat actorCVE-2023-2339760
Microsoft Warns of Kremlin-Backed APT28 Exploiting Critical Outlook VulnerabilityThe Hacker News·Dec 8, 08:55 UTC · Dec 8, 2023VulnerabilityCVE-2023-23397CVE-2023-3883160
Russia-Backed APT28 Tried to Attack Ukrainian Critical Power FacilityInfosecurity Magazine·Sep 6, 12:30 UTC · Sep 6, 2023Threat actor60
Cyber Command's latest VirusTotal upload has been linked to an active attackCyberScoop·May 21, 22:37 UTC · May 21, 2019Data breach in the wild60
Ukraine blames infamous Russian hackers for 'BadRabbit' ransomware attackCyberScoop·Nov 3, 04:22 UTC · Nov 3, 2017Ransomware in the wild60