Seven CVEs, One Doctrine: Why APT28 Is Quietly Infiltrating the Dutch Defense Supply Chain

Since 2022, APT28, the group operating under Russian GRU Unit 26165, has been conducting a sustained campaign against Western logistics and defense-related entities supporting Ukraine. NCSC-UK, ESET, and the French Ministry of Foreign Affairs confirm that at least twelve European countries are being targeted, including the Netherlands.

For 2026, Recorded Future’s Insikt Group identifies a shift in doctrine: no longer spectacular disruption, but disciplined pre-positioning in identity systems, edge appliances, and cloud environments. For Dutch shipyards, drone and ammunition suppliers, radar manufacturers, and logistics service providers in the Port of Rotterdam, this is not an abstract threat landscape, but a reality.

This means that the traditional perimeter-based approach is no longer sufficient. This article outlines the modus operandi, translates it into Zero Trust measures in accordance with NIST SP 800-207, and links the obligations under the Cybersecurity Act and BIO2 to concrete decisions at board level.

Actor Profile

APT28, designated as group G0007 in MITRE ATT&CK and known in vendor taxonomies as Fancy Bear (CrowdStrike), Forest Blizzard (Microsoft), and Sofacy (Kaspersky), is a group attributed to the Russian military intelligence service GRU, specifically Unit 26165 of the Main Intelligence Directorate. Fancy Bear has been operating since at least 2004 and is responsible for operations against NATO member states, election infrastructure, anti-doping organizations, and, since 2022, intensive targeting of Ukraine and the Western supply chains supporting it.

Insikt Group places Russia, alongside China, Iran, and North Korea, among the four most capable and consistently active hostile state cyber actors. The modus operandi in 2025–2026 is not spectacular disruption, but disciplined pre-positioning at the edges of the network, in VPN appliances, edge routers, and identity platforms where monitoring has historically been weak. A cluster operating under the APT28 umbrella is therefore also focused on the mass compromise of SOHO routers. Dark Reading reports that the group collects credentials by modifying DNS settings on vulnerable routers, a form of “malwareless” cyber espionage that evades traditional EDR detection. The group also uses compromised SOHO devices to host credential-phishing pages that imitate Western cloud email providers.

Targets and Motivation

The strategic motivation is disruption and reconnaissance of the Western logistics chain that facilitates military and humanitarian assistance to Ukraine. NCSC-UK refers in its advisory to “a serious risk to targeted organizations, including those involved in the delivery of assistance to Ukraine.” The geographic distribution of currently known victims includes Bulgaria, the Czech Republic, France, Germany, Greece, Italy, Moldova, the Netherlands, Poland, Romania, Slovakia, Ukraine, and the United States.

APT28’s focus includes the defense industry, transport and freight forwarding, maritime services, air traffic control, and ICT service providers serving these sectors. For the Netherlands, this specifically means that shipyards, drone and ammunition suppliers, radar and sensor manufacturers, logistics service providers in the Port of Rotterdam, and their ICT suppliers fall within the direct targeting profile.

Operation RoundPress, discovered by ESET and ongoing since 2023, illustrates the breadth of the campaign: espionage is conducted through XSS vulnerabilities in webmail systems (Roundcube, Horde, MDaemon, Zimbra) against governments and defense companies in Eastern Europe, as well as governments in Africa, Europe, and South America. The target profile therefore extends beyond organizations that directly supply Ukraine.

Seven Entry Points and a Preference for Living off the Land

APT28 uses seven entry points for initial access, as documented in the joint advisory issued by, among others, the NSA, FBI, NCSC-UK, and CISA:

  • Brute-force attacks to guess credentials, often in the form of password spraying against Microsoft 365 tenants [T1110.003].
  • Spearphishing for credential harvesting through spoofed login pages of governments and Western cloud email providers, hosted on free third-party services or compromised SOHO devices [T1566.002].
  • Spearphishing with malware as the payload [T1566.001].
  • Exploitation of the Outlook NTLM vulnerability CVE-2023-23397 [T1203].
  • Exploitation of Roundcube webmail (CVE-2020-12641, CVE-2020-35730, CVE-2021-44026).
  • Exploitation of internet-facing infrastructure such as corporate VPN appliances and SQL injection [T1190].
  • Exploitation of the WinRAR vulnerability CVE-2023-38831 through weaponized archives.

After initial access, a post-exploitation phase follows, focused on reconnaissance, persistence, and discreet data collection. The actor identifies individuals responsible for transport coordination and their external contacts, a step consistent with MITRE’s Account Discovery and Permission Groups Discovery techniques [T1087][T1069].

For lateral movement, the group deliberately uses living-off-the-land tooling. Impacket, PsExec, and RDP are used to move through the victim network without leaving large numbers of conspicuous custom binaries behind [T1021.001][T1021.002][T1570]. Credential theft from Active Directory is performed using Certipy (AD CS abuse) and ADExplorer.exe, a legitimate Sysinternals tool [T1003][T1207].

The characteristic end stage is the establishment of persistent email collection: the actor modifies Microsoft Exchange mailbox permissions and secures Office 365 user lists so that access persists even after credentials are rotated [T1114.002][T1098.002]. The Forest Blizzard cluster extends this with an almost malware-free technique: compromising SOHO routers and modifying a single DNS setting, thereby silently redirecting traffic from remote workers and small offices [T1584.005].

Recent Activity 2025–2026

While the campaigns of 2022–2024 largely relied on weaponized attachments and direct credential phishing, the actor has structurally shifted in 2025 and 2026 toward token theft, OAuth persistence, and compromise-through-adjacency. The activities below summarize publicly documented developments insofar as they are relevant to the Dutch defense supply chain.

Authentic Antics — NCSC-UK, July 2025

NCSC-UK published a malware analysis report on Authentic Antics, an implant developed by APT28 that runs within the Outlook process and steals OAuth refresh tokens for Microsoft 365. The implant displays fake Microsoft login prompts to users, intercepts the resulting tokens, and exfiltrates them to attacker-controlled Exchange accounts without generating outbound C2 traffic that can easily be blocked.

The technique bypasses conventional MFA because stolen refresh tokens already represent authenticated sessions [T1528][T1550.001]. For Dutch defense suppliers operating on Microsoft 365, this represents the most direct cloud-persistence threat of the past year.

NEARESTNEIGHBOR Operations — 2024, Continuing into 2025

Volexity documented that APT28 reached a U.S. target organization by first compromising an adjacent company, then associating with the Wi-Fi network of the intended victim from there, thereby completely bypassing perimeter controls. Similar patterns were observed in 2025 around defense and policy institutions in Europe.

For buildings in the Port of Rotterdam, The Hague, and the Eindhoven region, where defense suppliers often operate next door to consultancies, accountants, and coworking spaces, this represents a tangible physical-cyber risk [T1200][T1078].

Continued Exploitation of Microsoft Vulnerabilities

Microsoft Threat Intelligence confirmed that APT28 used CVE-2022-38028 (Windows Print Spooler privilege escalation) in 2024–2025 through the GooseEgg tool, particularly against Ukrainian, Western European, and North American government and defense targets.

CVE-2023-23397 (Outlook NTLM leak) also continues to be actively exploited where organizations have not fully implemented the patch or mitigation. In 2025, the actor was observed exploiting CVE-2025-24054 (Windows NTLM hash disclosure via .library-ms files), a variant that feeds the same NTLM relay chains as CVE-2023-23397 [T1187][T1212].

WinRAR CVE-2025-8088 — August 2025

ESET and BleepingComputer reported a path-traversal zero-day in WinRAR, CVE-2025-8088, which was used by multiple Russian state-linked clusters, including groups operating close to APT28, in spearphishing campaigns against defense and energy targets in Europe.

The pattern is identical to CVE-2023-38831: weaponized archives containing malicious path components that place a payload in autostart locations during extraction [T1203][T1547.001].

Roundcube CVE-2025-49113 and Subsequent RoundPress Campaigns

The Roundcube vulnerability CVE-2025-49113 (post-authentication remote code execution), patched in June 2025, was incorporated by APT28 into the RoundPress chain in the second half of 2025.

The actor combines credential phishing for Roundcube accounts with direct RCE after login, enabling the complete takeover of webmail servers belonging to governments and defense companies in Eastern Europe [T1190][T1505.003].

Cisco IOS XE Targeting — CVE-2018-0171, Reopened in 2025

Cisco Talos and Microsoft reported that Russian actors, overlapping with Forest Blizzard infrastructure, compromised large numbers of unmanaged Cisco network devices in 2025 through the Smart Install vulnerability CVE-2018-0171, including configuration exfiltration and the establishment of GRE tunnels to attacker infrastructure [T1584.008].

For defense suppliers, this means that legacy switches in production and engineering VLANs represent a direct pre-positioning vector.

Signal Device Linking and Messenger Targeting

Google Threat Intelligence Group reported in early 2025 that Russian actors, including GRU-linked clusters, abused QR-based device linking to silently associate Signal accounts belonging to Ukrainian military personnel, journalists, and policymakers with attacker devices.

By late 2025 and early 2026, the same technique had been observed against employees of European defense companies and think tanks that regularly communicate with Ukrainian counterparts [T1557].

Pre-positioning in Edge and Identity Infrastructure — Q1 2026

In line with the Insikt Group 2026 report, multiple incidents were reported in the first quarter of 2026 in which APT28 positioned itself in identity broker components (SAML IdP proxies, federation servers) and outbound management appliances.

The actor uses CVE-2026-21509, a vulnerability in widely deployed enterprise VPN/ZTNA appliances that enables session-cookie leakage, and combines it with passive tokens from previously compromised Authentic Antics sessions to regain access without new credentials [T1078.004][T1550.004].

Supply Chain Risks

The defense supply chain is a primary attack surface for APT28. The actor deliberately selects the weakest link in the chain and uses it as a stepping stone toward the ultimate target.

For a Dutch shipyard, radar manufacturer, or ammunition supplier, this means that its own security level is only one variable; the attacker looks for a gap at the engineering service provider, the ERP implementation partner, the MSP managing the CAD platform, or the logistics provider coordinating shipments to Ukraine.

Four categories of supply chain risks can be specifically identified in the context of APT28.

1. Compromise of Trusted ICT Service Providers and Managed Service Providers [T1199]

The joint advisory from the NSA, FBI, and NCSC-UK explicitly states that APT28 attacks ICT service providers to reach multiple end customers through their privileged management access.

A single compromised RMM agent or helpdesk console can provide access to dozens of defense-related customer environments, including domain administrator credentials and VPN profiles.

2. Software Supply Chain Attacks Through Development Chains and Update Mechanisms [T1195.002]

Defense suppliers that fail to segment development environments, CI/CD pipelines, and artifact repositories risk having a compromised build agent sign weaponized binaries with the supplier’s legitimate code-signing key.

3. Hardware and Firmware Compromise of Edge Devices [T1195.003][T1584.005]

The Forest Blizzard SOHO router campaign is the most tangible example. Remote workers at a defense supplier, or small satellite offices operated by subcontractors, may rely on consumer-grade routers that are never patched.

A single DNS modification on such a device routes all credentials to an APT28 proxy. The compromise does not occur at the supplier itself, but within the chain of user equipment that the supplier does not manage.

4. OAuth and SaaS-to-SaaS Supply Chain Risks

Defense engineering rarely relies exclusively on on-premises tooling. Production engineering, PLM platforms, DevOps tools, and collaboration platforms with partners and government ministries are connected to the primary Microsoft 365 or Google Workspace tenant through OAuth integrations.

APT28 abuses illicit consent grants to establish persistence that survives credential rotation and can subsequently reach the partner tenant through the primary supplier’s cloud identity graph.

Zero Trust Mitigations

The “assume breach” principle from NIST SP 800-207 is not a theoretical proposition for this threat, but the starting point. The mitigations are mapped to the seven Zero Trust pillars and linked to concrete vendor solutions.

Netskope One forms the backbone for SSE, ZTNA, SWG, CASB, and DLP; additional platforms fill the pillars where Netskope’s functionality intersects with identity, endpoint, or Active Directory.

IDENTITY

APT28 entry through password spraying and credential phishing requires phishing-resistant MFA (FIDO2, WebAuthn, certificate-bound authentication) for all users, not just administrators [T1110.003].

Microsoft Entra ID P2 provides the identity provider functionality, including risk-based conditional access and Identity Protection signals such as impossible travel, leaked credentials, and atypical location.

For high-assurance authentication, Yubico YubiKey or HID Crescendo provide hardware tokens. Step-up MFA is mandatory for mailbox delegation and other sensitive operations.

Netskope integrates with Entra ID through SCIM and SAML and uses identity context in the Zero Trust Engine for per-session authorization.

ENDPOINT

Behavioral detection of Impacket, PsExec, and ADExplorer requires a full-featured EDR platform. CrowdStrike Falcon Insight XDR or Microsoft Defender for Endpoint P2 provide this detection, including Attack Surface Reduction rules that block Office child processes and LOLBin abuse.

Continuous device posture is provided to the Zero Trust Engine by Netskope Device Intelligence and the Netskope Client, preventing unmanaged devices from accessing defense applications without Netskope Remote Browser Isolation.

For OT and IoT visibility, Armis or Claroty xDome fill the blind spots that conventional EDR does not cover.

DATA

Defense project data is the protect surface. Netskope Next Gen SWG and Netskope CASB provide inline DLP with OCR for documents, preventing ITAR, EAR, and NATO classifications from leaking through SaaS or webmail.

Microsoft Purview Information Protection adds persistent labeling and rights management to the data itself.

Encryption at rest and in transit is provided through AWS KMS, Azure Key Vault, or Thales CipherTrust, in accordance with NIST SP 800-207.

Netskope Public Cloud Security (SSPM/DSPM) detects incorrectly shared buckets and OAuth consent grants that APT28 could abuse as a persistence mechanism.

APPLICATIONS

Exchange mailbox permission changes are alerted on and periodically reconciled through Microsoft Defender for Office 365 in combination with SIEM correlation [T1098.002].

Legacy webmail (Roundcube, Horde, Zimbra) is either phased out or placed behind Netskope Private Access (ZTNA) with application-specific policies.

Netskope SaaS Security Posture Management detects risky OAuth consent grants and admin drift in Microsoft 365, Google Workspace, and Salesforce.

For custom engineering applications, Netskope Private Access Publisher provides a clientless broker without exposing the application to the public internet.

INFRASTRUCTURE

Internet-facing VPN appliances are replaced, for example, by Netskope Private Access as the Policy Enforcement Point, in accordance with the PEP model from SP 800-207.

This eliminates, in one move, the Ivanti, Fortinet, and Citrix VPN appliances that APT28-like actors have demonstrably targeted.

SOHO router compromise is mitigated because the Netskope Client tunnels traffic in encrypted form to the NewEdge cloud, meaning that a modified DNS setting on a home router can no longer result in credential interception.

Cloud workloads are protected with Wiz or Netskope Cloud Security Posture Management against misconfigurations.

NETWORK

Application-level microsegmentation, rather than network-level segmentation, replaces flat VLANs across which RDP and SMB can flow freely [T1021].

Illumio Core or Akamai Guardicore Segmentation provides host-based microsegmentation for data center workloads; for user-to-application segmentation, Netskope Private Access takes control.

The Netskope Zero Trust Engine acts as the Policy Engine, making decisions per session based on identity, device posture, location, and threat intelligence.

VISIBILITY AND ANALYTICS

The Trust Algorithm is fed by CDM/ICAM, SIEM telemetry, PKI events, and threat intelligence feeds relating to APT28 infrastructure.

Microsoft Sentinel or Splunk Enterprise Security aggregates logs; Recorded Future Intelligence Cloud provides APT28-specific threat intelligence through STIX/TAXII.

Microsoft Defender for Identity and Semperis DSP provide Identity Threat Detection and Response across Entra ID and on-premises Active Directory, including detection of Certipy-like AD CS abuse.

Netskope Advanced Analytics correlates user, application, and data flows in the Netskope NewEdge cloud and feeds normalized events into the SIEM.

Compliance Impact

For Dutch defense suppliers that also purchase or provide financial services—for example trade finance, export credit insurance through Atradius DSB, or services to banks serving defense customers—the threat directly affects multiple DORA articles.

Article 5 requires an ICT risk management framework under the direct responsibility of the management body; the APT28 campaign against logistics chains is precisely the type of scenario that this framework must anticipate.

Article 9(4)(b) and (d) requires the protection of ICT assets and network security, which has direct implications for securing VPN appliances, Exchange servers, and Roundcube deployments actively exploited by APT28.

Article 11 requires detection and response capabilities appropriate to the complexity of the identified threats; APT28’s malwareless techniques against SOHO routers require network telemetry beyond the traditional EDR layer.

Major ICT incidents must be classified under Article 17 and reported to the competent authority in accordance with Articles 19–23.

For large entities, threat-led penetration testing (TLPT) is mandatory every three years under Article 26, with the Target Threat Intelligence Report explicitly required to incorporate current threats such as APT28 into the scenario selection.

Third-party risk management under Article 28 is crucial because APT28 deliberately attacks supply-chain partners and ICT service providers to reach the ultimate target.

The Dutch Cybersecurity Act implements NIS2 and applies to defense suppliers that fall under essential or important entities in the sectors of digital infrastructure, production of defense-related goods, or transport.

Article 24 of the Cbw requires appropriate technical, operational, and organizational measures, substantively based on the ten minimum measures in Article 21(2) of NIS2.

For the APT28 threat, the following are particularly relevant:

  • risk analysis (a), including geopolitical threat modeling;
  • incident handling (b), with 24-hour early warning under Article 23;
  • basic cyber hygiene and training (g), specifically awareness of spearphishing and RoundPress-like webmail exploits;
  • cryptography (h) for secure communications; and
  • MFA and authentication policies (j), directly targeting password spraying.

Supply chain measures (d) are crucial because APT28 deliberately gains access through service providers.

Board liability under Article 20 of NIS2 means that management is accountable for failing to implement patches for known, actively exploited CVEs such as CVE-2023-23397 and CVE-2023-38831.

For defense suppliers carrying out contracts for the Ministry of Defence, the Rijksrederij, or other Dutch government bodies, BIO2 applies contractually.

APT28 TTPs directly affect five key controls. Malware protection under BIO2-8.07 covers not only traditional antivirus, but also behavioral detection for PRISMEX and living-off-the-land tooling.

Technical vulnerability management under BIO2-8.08 requires a structured patching process that closes the seven APT28 entry CVEs within defined SLAs.

Network security under BIO2-8.20 and network segmentation under BIO2-8.22 address lateral movement through RDP, PsExec, and Impacket and require microsegmentation between engineering VLANs and corporate ICT.

Application security requirements under BIO2-8.26 explicitly cover the choice of modern, maintained webmail instead of legacy Roundcube deployments.

In addition, logging and monitoring are required to detect Exchange permission changes and AD enumeration by APT28.

Detection and Monitoring

Detecting APT28 requires a layered approach within the Detect function of the NIST CSF. The group leaves few traditional IOCs behind, making behavior-based detection engineering (TTP detection) essential.

At the identity level, correlation between failed logins, impossible travel, and token issuance is critical. Okta and Entra ID provide sign-in risk signals that can be correlated with endpoint telemetry through the SIEM. For [source text is incomplete here: “Voor helpt monitoring van nieuwe OAuth-app-consents en API-call-anomalieën.”]

At the network level, SSL inspection is central. SWG logs from Netskope or Zscaler should log domain reputation, JA3 fingerprints, and upload volumes.

Outbound traffic to Dropbox, OneDrive, Telegram, and Cloudflare Workers should have baseline behavior established for each user.

For DNS hijacking through SOHO routers, authoritative DNS logging and comparison against known resolvers are necessary: a user who suddenly resolves names through an unusual DNS server is suspicious.

At the endpoint level, EDR detects behavioral patterns such as Office child processes (WINWORD.EXE spawning mshta/rundll32), exploit signatures in documents, and credential access.

Sigma rules linked to MITRE ATT&CK mappings in Netskope and other tooling accelerate coverage analysis.

At the application level, CASB audits of cloud API activity provide visibility into [source text ends here]: bulk downloads from SharePoint or Confluence by unrelated users are a priority indicator.

Recommendations

The following recommendations are proposed and prioritized according to their impact against APT28.

  • Patch Microsoft Office, Roundcube, Zimbra, and edge devices (TP-Link and other SOHO routers) as a priority; validate that CVE-2026-21509, CVE-2026-21513, and CVE-2023-50224 are covered.
  • Replace remote-access VPN with ZTNA featuring per-application access and device posture checks; reduce trusted-relationship risk by enforcing least-privilege access for third parties.
  • Enforce MFA at every access point, without exceptions, and add conditional access based on risk scores; implement step-up authentication for privileged operations.
  • Enable SSL inspection with sandboxing on all outbound traffic, including popular cloud services (Dropbox, OneDrive, Telegram), to detect ingress tool transfer and exfiltration over web services.
  • Implement UEBA across identities and data access to detect anomalous behavior and potential compromise; link alerts to the SOAR playbook for APT28 attribution indicators.
  • Establish a detection roadmap based on the APT28 ATT&CK profile and measure coverage per technique; use this profile as a scenario for the mandatory TLPT under DORA.
  • Operationalize incident reporting: establish playbooks for 24-hour early warning, 72-hour full notification, and a one-month final report, aligned with both DORA supervisory requirements (DNB/AFM) and the Cbw-CSIRT and relevant sectoral regulator.
  • Incorporate SOHO router risk into BYOD and remote-working policies: provide corporate-managed routers or mandate split tunneling with ZTNA, because APT28’s FrostArmada campaign uses home infrastructure as a stepping stone.
  • Conduct a supply-chain assessment of IT suppliers and MSPs in accordance with Article 28 of DORA and Article 21(2)(d) of NIS2; contractually require incident notification, mandatory MFA, and ZTNA deployment by third parties.
  • Increase board-level awareness: directors must understand the APT28 threat profile and approve proportionate measures, in accordance with board responsibilities under the Cbw and Article 20 of NIS2.

Leave a Comment