Campaign, Feb 2022 to Nov 2024.View on attack.mitre.org
APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily leveraged living-off-the-land techniques, while leveraging the zero-day exploitation of CVE-2022-38028. Notably, APT28 leveraged Wi-Fi networks in close proximity to the intended target to gain initial access to the victim environment. By daisy-chaining multiple compromised organizations nearby the intended target, APT28 discovered dual-homed systems (with both a wired and wireless network connection) to enable Wi-Fi and use compromised credentials to connect to the victim network.
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
During APT28 Nearest Neighbor Campaign, APT28 used the following commands to dump SAM, SYSTEM, and SECURITY hives: |
| T1003.003 NTDS |
During APT28 Nearest Neighbor Campaign, APT28 dumped NTDS.dit through creating volume shadow copies via |
| T1006 Direct Volume Access |
During APT28 Nearest Neighbor Campaign, APT28 accessed volume shadow copies through executing |
| T1016.002 Wi-Fi Discovery |
During APT28 Nearest Neighbor Campaign, APT28 collected information on wireless interfaces within range of a compromised system. |
| T1021.001 Remote Desktop Protocol |
During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally. |
| T1059.001 PowerShell |
During APT28 Nearest Neighbor Campaign, APT28 used PowerShell cmdlet |
| T1059.003 Windows Command Shell |
During APT28 Nearest Neighbor Campaign, APT28 used |
| T1074.001 Local Data Staging |
During APT28 Nearest Neighbor Campaign, APT28 staged captured credential information in the |
| T1090.001 Internal Proxy |
During APT28 Nearest Neighbor Campaign, APT28 used the built-in |
| T1110.003 Password Spraying |
During APT28 Nearest Neighbor Campaign, APT28 performed password-spray attacks against public facing services to validate credentials. |
| T1140 Deobfuscate/Decode Files or Information |
During APT28 Nearest Neighbor Campaign, APT28 unarchived data using the GUI version of WinRAR. |
| T1560.001 Archive via Utility |
During APT28 Nearest Neighbor Campaign, APT28 used built-in PowerShell capabilities ( |
| T1561.001 Disk Content Wipe |
During APT28 Nearest Neighbor Campaign, APT28 used the native Microsoft utility cipher.exe to securely wipe files and folders – overwriting the deleted data using |
| T1567 Exfiltration Over Web Service |
During APT28 Nearest Neighbor Campaign, APT28 exfiltrated data over public-facing webservers – such as Google Drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.