Netcrook Logo

Tag: APT28

24 article(s)

Invisible Intruders: Russia’s APT28 Hacked Microsoft Accounts Without Malware

09 Apr 2026 news 🌍 Europe

Russia’s APT28, in the FrostArmada campaign, compromised thousands of routers worldwide to steal Microsoft credentials—without using malware. Learn how the attack worked, who was targeted, and what it means for the future of network security.

#APT28 | #FrostArmada | #DNS Hijacking

Stealth in the Shadows: APT28’s PRISMEX Malware Campaign Hits Ukraine and NATO

08 Apr 2026 news 🌍 Europe

Russian hacking group APT28 has launched a sophisticated PRISMEX malware campaign against Ukraine and NATO, exploiting zero-days and advanced stealth tactics to compromise vital sectors and threaten both espionage and sabotage.

#APT28 | #PRISMEX | #Cyber-espionage

Invisible Siege: Pro-Russian Hackers Hijack Routers Worldwide

08 Apr 2026 news 🌍 Europe

A sweeping cyberattack by pro-Russian group APT28 has compromised thousands of home and business routers, putting user credentials and internet traffic at risk. Authorities are racing to dismantle the botnet and secure vulnerable devices.

#Cybersecurity | #APT28 | #Router

U.S. Agents Dismantle Russian Router Espionage Network

08 Apr 2026 news 🌍 Europe

U.S. law enforcement and global tech firms have dismantled a sprawling Russian cyber-espionage operation that hijacked home and office routers in over 120 countries. Here’s how the attackers exploited DNS and router vulnerabilities—and how the takedown unfolded.

#Cyber Espionage | #APT28 | #DNS Hijacking

GhostMail: Russian Hackers Exploit Zimbra Flaw to Breach Ukrainian Government

19 Mar 2026 news 🌍 Europe

APT28, a Russian state-backed hacking group, exploited a critical Zimbra email vulnerability in attacks on Ukrainian government agencies. The stealth campaign, dubbed Operation GhostMail, highlights the escalating cyberwar tactics targeting state infrastructure.

#GhostMail | #APT28 | #Zimbra

Shadow Play: Russian APT28 Deploys BEARDSHELL, COVENANT in Ukraine Espionage Blitz

10 Mar 2026 news 🌍 Europe

Russian state-backed hacking group APT28 is targeting Ukrainian military personnel with advanced malware implants BEARDSHELL and COVENANT, leveraging cloud services and sophisticated obfuscation to maintain covert surveillance.

#APT28 | #Cyberwarfare | #Malware

Shadow Resurgence: Russia’s APT28 Hackers Relaunch Advanced Cyber Attacks on Ukraine

10 Mar 2026 news 🌍 Europe

Russian hacking group APT28 has reactivated advanced malware campaigns against Ukraine, deploying new tools like BeardShell and Covenant in a renewed wave of espionage. Experts warn this marks a major escalation in cyber hostilities.

#APT28 | #Cyberwar | #Malware

APT28 Supercharges Espionage with Customized Covenant Malware

10 Mar 2026 news 🌍 Europe

APT28, Russia’s infamous state-backed hackers, have weaponized open-source frameworks like Covenant and cloud storage providers to launch sophisticated espionage campaigns targeting Ukrainian and European entities. Their technical evolution marks a dangerous new chapter in cyber warfare.

#APT28 | #cyber-espionage | #open-source tools

APT28 Exploits MSHTML Zero-Day: Russian Hackers Breach Windows Before Patch

02 Mar 2026 news 🌍 Europe

Russian state-backed hackers APT28 exploited a Windows MSHTML zero-day before Microsoft’s patch, using malicious shortcut files to bypass security and compromise systems worldwide.

#APT28 | #MSHTML | #zero-day

APT28 Exploits MSHTML Zero-Day Before Patch | Netcrook Criminal Chronicles

02 Mar 2026 news 🌍 Europe

APT28 exploited a critical MSHTML zero-day vulnerability before Microsoft’s February 2026 patch, using malicious LNK files to bypass protections and execute code. The attack highlights evolving tactics and ongoing risks from state-sponsored cyber actors.

#APT28 | #MSHTML vulnerability | #zero-day exploit