← Back to BrewedIntel
adversaryhighAdvanced Persistent ThreatCyber EspionageSednit

Mar 10, 2026 • ESET WeLiveSecurity

Sednit reloaded: Back in the trenches

Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed...

Source
ESET WeLiveSecurity
Category
adversary
Severity
high

Executive Summary

Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed activity. This APT group has historically targeted government, defense, and media organizations for espionage purposes. The resurgence indicates continued investment in cyber espionage capabilities by Russian threat actors. Organizations should ensure robust detection mechanisms, monitor for APT28-associated TTPs, and maintain updated threat intelligence to defend against this persistent threat actor known for its complex tooling and persistent operations.

Summary

The resurgence of one of Russia’s most notorious APT groups

Published Analysis

Sednit, also known as APT28 or Fancy Bear, one of Russia's most sophisticated and notorious state-sponsored threat groups, has resurfaced with renewed activity. This APT group has historically targeted government, defense, and media organizations for espionage purposes. The resurgence indicates continued investment in cyber espionage capabilities by Russian threat actors. Organizations should ensure robust detection mechanisms, monitor for APT28-associated TTPs, and maintain updated threat intelligence to defend against this persistent threat actor known for its complex tooling and persistent operations. The resurgence of one of Russia’s most notorious APT groups The resurgence of one of Russia’s most notorious APT groups

Linked Entities

  • Sednit