APT 28 “Fancy Bear” threat modeling

An in-depth look at the history of Advanced Persistent Threat (APT) 28, often referred to as “Fancy Bear” completed as my undergraduate capstone project.

table of contents:

  • history, origins, motives
  • APT 28 mapped to MITRE ATT&CK *
  • attack analysis *
    • used ELK stack to analyze a multi-stage APT28 attack
    • an exploration of the tools and techniques used
    • documentation following the APT from initial access → privilege escalation → discovery and lateral movement → defense evasion → exfiltration
  • lessons learned and defensive takeaways Since this was completed as a group project, I must specify that the bulk of my efforts were put into the sections denoted with an asterisk (*)

attack analysis:

📕Attack_Analysis-gs.pdf

APT 28 mapped to MITRE ATT&CK

📎apt28_2625.xlsx

Full Presentation

📕APT28.pdf

Last updated: July 30, 2026