Pawn Storm

Threat Actor updated 10 days ago (2024-10-17T13:01:56.647Z)
Download STIX
Preview STIX
Pawn Storm, also known as APT28, Fancy Bear, Sofacy Group, Sednit, BlueDelta, and STRONTIUM, is a threat actor that has been active since at least 2007. The group is notorious for its complex operations that steal victims' credentials to enable surveillance or intrusion operations. It has targeted governments, militaries, and security organizations worldwide, employing various techniques such as shell scripts, SSH tunneling, credential phishing, and NTLMv2 hash relay attacks. The group's activities escalated in sophistication from April 2023, when it began using more elaborate methods in its attacks. Pawn Storm employed VPN services and established credential phishing websites using webhooks, with notable activity recorded in November and December of 2023. Additionally, the group exploited the EdgeRouter botnet, which dates back to 2016, for various purposes after likely brute-forcing the credentials of backdoored SSH servers. In January 2024, the US FBI disrupted the EdgeRouter botnet used by Pawn Storm. During the subsequent investigation into a Linux botnet targeted in this takedown, researchers discovered another Linux botnet running on some of the same EdgeRouters previously exploited by Pawn Storm. These compromised routers could be easily abused by Pawn Storm or any other threat actor due to poor protection by the criminal botnet operator. This information underscores the persistent and evolving threat posed by Pawn Storm and emphasizes the importance of robust cybersecurity measures.
Description last updated: 2024-10-17T12:14:31.309Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
APT28 is a possible alias for Pawn Storm. APT28, also known as Fancy Bear, Forest Blizzard, and Unit 26165 of the Russian Main Intelligence Directorate, is a Russia-linked threat actor that has been active since at least 2007. This group has targeted governments, militaries, and security organizations worldwide with a particular focus on th
7
Forest Blizzard is a possible alias for Pawn Storm. Forest Blizzard, also known as APT28, Fancy Bear, and Strontium, is a threat actor linked to the Russian General Staff Main Intelligence Directorate (GRU) and the 85th Main Special Service Center (GTsSS). The group has been involved in persistent espionage campaigns against European countries, which
4
Sednit is a possible alias for Pawn Storm. Sednit, also known as APT28, Fancy Bear, Pawn Storm, Sofacy Group, BlueDelta, and Strontium, is a threat actor associated with Russia's military intelligence. The group has been active since at least 2007, primarily targeting governments, militaries, and security organizations worldwide. Notably, Se
3
Fancy Bear is a possible alias for Pawn Storm. Fancy Bear is a sophisticated Russian-based threat actor, also known as Sofacy or APT 28, that has been active since the mid-2000s. Fancy Bear is responsible for targeted intrusion campaigns against the Aerospace, Defense, Energy, Government and Media sectors. At the DNC, both Cozy Bear and Fancy Be
3
Sofacy is a possible alias for Pawn Storm. Sofacy is a threat actor group that has been observed using multiple languages to create variants of the Zebrocy Trojan and Cannon. In one campaign, they relied heavily on filenames to lure victims into launching weaponized documents. The group packed only Delphi variants in an attempt to increase e
2
IRON TWILIGHT is a possible alias for Pawn Storm. IRON TWILIGHT is a threat actor believed to be associated with the GRU, Russia's military intelligence agency. This association has been suggested by various researchers, including those from CrowdStrike and CTU, based on the characteristics of the group's activities. The group became particularly a
2
STRONTIUM is a possible alias for Pawn Storm. Strontium, also known as APT28, Fancy Bear, Forest Blizzard, and several other names, is a threat actor linked to Russia's General Staff Main Intelligence Directorate (GRU). Active since at least 2007, the group has targeted governments, militaries, and security organizations worldwide. Strontium's
2
Sofacy Group is a possible alias for Pawn Storm. The Sofacy Group, also known as APT28, Fancy Bear, Pawn Storm, Sednit, BlueDelta, and STRONTIUM, is a well-established threat actor that has been active since at least 2007. This group, which could be an individual, a private company, or part of a government entity, has targeted governments, militar
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Apt
Phishing
Exploit
Spam
Botnet
Linux
Malware
Vpn
Proxy
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Pawn Storm Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
BankInfoSecurity
2 months ago
Securityaffairs
2 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Trend Micro
6 months ago
Securityaffairs
6 months ago
CERT-EU
8 months ago
Securityaffairs
8 months ago
Checkpoint
9 months ago
Trend Micro
9 months ago
Securityaffairs
a year ago
Unit42
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
Securityaffairs
a year ago
MITRE
2 years ago
MITRE
2 years ago
MITRE
2 years ago