Mar 10, 2026 • ESET WeLiveSecurity
Sednit reloaded: Back in the trenches
Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed...
Executive Summary
Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed activity. This APT group has historically targeted government, defense, and media organizations for espionage purposes. The resurgence indicates continued investment in cyber espionage capabilities by Russian threat actors. Organizations should ensure robust detection mechanisms, monitor for APT28-associated TTPs, and maintain updated threat intelligence to defend against this persistent threat actor known for its complex tooling and persistent operations.
Summary
The resurgence of one of Russia’s most notorious APT groups
Published Analysis
Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed activity. This APT group has historically targeted government, defense, and media organizations for espionage purposes. The resurgence indicates continued investment in cyber espionage capabilities by Russian threat actors. Organizations should ensure robust detection mechanisms, monitor for APT28-associated TTPs, and maintain updated threat intelligence to defend against this persistent threat actor known for its complex tooling and persistent operations. The resurgence of one of Russia’s most notorious APT groups The resurgence of one of Russia’s most notorious APT groups
Linked Entities
- Sednit