#Sofacy
You might remember in 2016 when Fancy Bear hacked the DCCC and leaked documents. You may not realize that Fancy Bear is a trade name for a group that other companies call also called: Sofacy, Pawn Storm, Strontium, APT 28, and Tsar Team, and the government called Grizzley Steppe. 🧵
Microsoft and CrowdStrike are teaming up to create alignment across our threat actor taxonomies, mapping where knowledge of these actors align to enable security professionals to connect insights faster and make decisions with greater confidence. https://msft.it/63327SlOeJ
Announcing a new strategic collaboration to bring clarity to threat actor naming | Microsoft Security Blog
Microsoft and CrowdStrike are teaming up to create alignment across our individual threat actor taxonomies to help security professionals connect insights faster.
msft.it
June 2, 2025 at 4:44 PM
2/2

Information:
APT28 : groupe de cyberespionnage lié à la Russie

APT (Advanced Persistent Threat | Menace Persistante Avancée)

Ce MOA (Mode Opératoire d’Attaque) est également documenté sous les noms de UAC-0028, Fancy Bear, FrozenLake, Sednit, Sofacy ou encore Pawn Storm.
April 29, 2025 at 4:02 PM
Russian state hackers APT28 (Fancy Bear/Forest Blizzard/Sofacy) breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique called "nearest neighbor attack."

www.bleepingcomputer.com/news/securit...
Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
Russian state hackers APT28 (Fancy Bear/Forest Blizzard/Sofacy) breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique called ...
www.bleepingcomputer.com
November 22, 2024 at 8:35 PM
This is embarrassing for an industry that's more than a decade old. "When the US gov issued a report about hacking attempts against the 2016 election...it [listed] 48 separate nicknames [for] Russian hacking groups...including 'Sofacy,' 'Pawn Storm,' 'CHOPSTICK,' 'Tsar Team,' and 'OnionDuke'"
June 2, 2025 at 4:42 PM
APT28 has "no fewer than 28 aliases"

Nice job, infosec!

blog.sekoia.io/apt28-operat...
September 16, 2025 at 4:14 PM
I think it's from the strings Sofacy and Cozer in their malware. Bear is a subtle nod to the suspected country of origin...
May 11, 2025 at 3:04 PM
Bear means Russian. Fancy comes from someone saw “sofacy” in their malware, making them think of the Iggy Azalea song.
July 6, 2025 at 10:42 PM
“Fancy” came from an analyst thinking of Iggy Azalea while working Sofacy. Can’t confirm that “Cozy” comes from Cozer but it’s likely. I highly doubt any of the people involved were aware of the other connotations. The “Bear” part came from an established, albeit somewhat juvenile, naming convention
May 11, 2025 at 8:43 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 7, 2026 at 3:39 PM
CrowdStrike names all Russian groups "bears." On day, someone emailed to ask about their name for Sofacy. It was the height of Iggy Azalea's hit single So Fancy. They didn't have a name, so on the spot an employee named them Iggy Bear. It was later renamed Fancy Bear.
June 2, 2025 at 5:20 PM
🇺🇸Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the GRU. www.justice.gov/opa/pr/justi...
Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU)
A January 2024 court-authorized operation has neutralized a network of hundreds of small office/home office (SOHO) routers that GRU Military Unit 26165, also known as APT 28, Sofacy Group, Forest Bliz...
www.justice.gov
February 16, 2024 at 4:44 AM
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu...
#BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
www.recordedfuture.com
December 17, 2025 at 3:46 PM
So how do all of these names get named?

Sofacy was originally named after the malware they used (Sofacy), which was in turn named after a text string found in a file.

Pawn Storm is a chess move that the group reminded the company Trend Micro of.
You might remember in 2016 when Fancy Bear hacked the DCCC and leaked documents. You may not realize that Fancy Bear is a trade name for a group that other companies call also called: Sofacy, Pawn Storm, Strontium, APT 28, and Tsar Team, and the government called Grizzley Steppe. 🧵
Microsoft and CrowdStrike are teaming up to create alignment across our threat actor taxonomies, mapping where knowledge of these actors align to enable security professionals to connect insights faster and make decisions with greater confidence. https://msft.it/63327SlOeJ
June 2, 2025 at 5:18 PM
This is the first post in a series about #Russia 's APT 28, aka Fancy Bear or Sednit, Sofacy, Forest Blizzard and many other names. There's been an exceptionally long trail of attacks and destruction this APT has been involved with, since early 2000s. #Ukraine #Georgia #NAFO #CyberSec
September 7, 2024 at 9:34 PM
🐻 Verantwortlich für die Angriffe: Einheit 26165 des russischen Militärgeheimdienstes GRU und die dazugehörige Gruppe APT28 (auch bekannt als Fancy Bear, Sofacy, Forest Blizzard).
May 21, 2025 at 1:10 PM
"of hundreds of small office/home office (SOHO) routers that GRU Military Unit 26165, also known as APT 28, Sofacy Group, Forest Blizzard, Pawn Storm, Fancy Bear, and Sednit, used to conceal and otherwise enable a variety of crimes"
February 15, 2024 at 6:23 PM
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
September 16, 2025 at 9:24 AM