Threat Actor
APT28
- First Reported
- May 21, 2026
- Latest Reported
- Aug 19, 2026
Reported Context (2)
- One of the designations presented for the actor to which CERT-UA attributed LAMEHUG with medium confidence; the article also gives UAC-0001 and IRON TWILIGHT. Sophos Finds Fake AI Installers Dominated Malware Cases
- Tentatively attributed actor for the macOS-focused Phexia activity, which may also be linked to Amatera. Hunt.io Report Maps 1,357 C2 Servers Across 98 Middle Eastern Providers
CVE (3)
Malware (20)
People (1)
Threat Actors (10)
MITRE ATT&CK (11)
Vendors (25)
Products (18)
Tools (11)
Industries (6)
Countries (16)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.