State-Sponsored APT
Advanced Persistent ThreatNemesis Bear
Origin: Russia | Active Since: 2004
// AI Dossier Summary
Nemesis Bear (APT28/Fancy Bear) is a Russian military intelligence (GRU) affiliated threat group known for cyber espionage and political interference campaigns.
// Group Fingerprint
- Primary Name
- Nemesis Bear
- Known Aliases
- APT28, Fancy Bear, Sofacy
- State Sponsor
- State-Sponsored (GRU)
- Motivations
- Espionage, Political Interference
- Primary Targets
- Government, Military, Media
- Active Since
- 2004
// Tradecraft & Arsenal
Known Malware Arsenal
- X-Agent
- Zebrocy
- Drovorub
Target Industries
- Government
- Military
- Media
MITRE ATT&CK Mapping
- T1078Valid Accounts
- T1110Brute Force