Threats · 96 days ago

APT28’s tooling is now disposable

APT28 is becoming harder to catch by design. The group is moving away from one stable implant and toward short-lived modules, edge-hosted infrastructure, and malware that can interact with an LLM, which shortens the window where any one fingerprint stays useful.

Sekoia’s report says this is an evolution in tradecraft, not just a new target set. It ties the shift to APT28’s long-running activity against government, defense, diplomatic, and critical infrastructure targets, and frames the change as a move from reusable indicators to rapidly replaced collection pieces.

For hunters, the break is in the operating model: one module or one node no longer tells you much about the rest of the campaign. The same actor can now look like a sequence of small, low-signal events that expire before traditional indicator-based tracking catches up.

CVE-2023-23397

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: microsoft Outlook Elevation of Privilege Vulnerability EPSS 97% (100th percentile).

CISA federal remediation date Apr 4 · date passed

CVE-2022-38028

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: windows Print Spooler Elevation of Privilege Vulnerability EPSS 15% (96th percentile).

CISA federal remediation date May 14 · date passed

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-06-12

Editions

Related stories