Frozenlake, also known as APT28, Fancy Bear, Forest Blizzard, and several other names, is a threat actor believed to be sponsored by the Russian military. The group has been involved in numerous cyber-attacks, primarily targeting Ukraine's energy sector. Their modus operandi includes exploiting vulnerabilities such as the WinRAR flaw to deploy malware, often through sophisticated phishing operations. These campaigns have been observed throughout 2021, with notable global operations occurring in September and October. The group's activities were analyzed in detail by Mandiant, which identified Frozenlake's involvement in a global phishing operation conducted in late 2021. CERT-UA, Ukraine's computer emergency response team, also reported that Frozenlake exploited the WinRAR vulnerability to target energy infrastructure in September 2021. Furthermore, Frozenlake was linked to the distribution of IRONJAW malware, first observed in late July through early August, hosted on free hosting providers. Various cybersecurity entities have attributed attacks to Frozenlake. Microsoft referred to the group as Forest Blizzard (formerly Strontium), while others like Recorded Future identified their spear-phishing campaigns under the name BlueDelta. In addition to their primary focus on Ukraine, overlaps in victimology suggest some level of cooperation between Frozenlake and another Russian nation-state actor known as Sofacy. The group has also been associated with the exploitation of CVE-2023-38831, a vulnerability used in a campaign against Ukraine’s energy infrastructure.
Associated Threat Actors
The APT28 Threat Actor is associated with Frozenlake. APT28, also known as Fancy Bear, Forest Blizzard, and Unit 26165 of the Russian Main Intelligence Directorate, is a Russia-linked threat actor that has been active since at least 2007. This group has targeted governments, militaries, and security organizations worldwide with a particular focus on thhas used
The Sandworm Threat Actor is associated with Frozenlake. Sandworm, also known as APT44, is a Russia-linked threat actor that has been implicated in several major cyberattacks. This group has been particularly active against targets in Ukraine and Poland, with significant operations including the compromise of 11 Ukrainian telecommunications providers, whiUnspecified
The Forest Blizzard Threat Actor is associated with Frozenlake. Forest Blizzard, also known as APT28, Fancy Bear, and Strontium, is a threat actor linked to the Russian General Staff Main Intelligence Directorate (GRU) and the 85th Main Special Service Center (GTsSS). The group has been involved in persistent espionage campaigns against European countries, whichhas used
