Sofacy Group — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
February 3, 2026
Last Seen
March 20, 2026

Related Threat Clusters

  • Russian APT Exploits Zimbra XSS to Target Ukrainian Government

    A Russian state-linked advanced persistent threat (APT) has targeted a Ukrainian government agency through a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite, identified as CVE-2025-66376. The…

    4 articles · Updated March 20, 2026
  • APT28 Revives Advanced Malware Toolkit for Cyber-Espionage

    APT28, a Russian threat actor, has reactivated its malware development team and deployed a modern espionage toolkit that includes a customized version of the Covenant open-source tool. This resurgence indicates a…

    10 articles · Updated March 10, 2026
  • APT28's Operation MacroMaze: Macro Malware Campaign Targets Europe

    APT28, a Russia-linked advanced persistent threat group, conducted a cyberespionage campaign named Operation MacroMaze from September 2025 to January 2026. The campaign involved deploying macro malware embedded in…

    3 articles · Updated February 24, 2026
  • Cyberattacks Target Ukraine and EU via Microsoft Office Vulnerability

    CERT-UA has reported a new wave of cyberattacks targeting Ukrainian government agencies and EU organizations, exploiting the Microsoft Office vulnerability CVE-2026-21509. Attackers are using malicious emails disguised…

    59 articles · Updated February 2, 2026

Recent Intelligence Reports

  • Russian APT weaponizes critical Zimbra bug in Ukraine-targeted intrusions — Scworld · March 20, 2026
  • APT28 conducts long — Securityaffairs.Co · March 10, 2026
  • Operation MacroMaze: APT28 exploits webhooks for covert data exfiltration — Securityaffairs.Co · February 24, 2026
  • APT28 exploits Microsoft Office flaw in Operation Neusploit — Securityaffairs.Co · February 3, 2026

CVSS v3.1 Breakdown