
FrostArmada
A threat cluster tracked internally by ReliaQuest, cited as a tradecraft overlap with the hotel router campaign.
FrostArmada is the internal threat-cluster label ReliaQuest cited as a tradecraft overlap with a hotel WiFi credential-theft campaign it reported on 23 July 2026.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Is FrostArmada the same threat actor as APT28?
Timeline for FrostArmada
One firm hedged, heise online named APT28
Cybersecurity: Threats and DefencesBackground
FrostArmada is a threat cluster tracked internally by ReliaQuest. Almost nothing about it is public beyond that single reference: ReliaQuest cited tradecraft overlap with FrostArmada when assessing a hotel WiFi credential-theft campaign, while explicitly stating the current activity differs from FrostArmada's prior behaviour.
No nationality, state sponsorship or link to a named advanced persistent threat group is established for FrostArmada in current reporting; heise online's separate attribution of the hotel WiFi campaign to APT28 is heise online's own claim, not ReliaQuest's, and does not establish FrostArmada as APT28.
This page is deliberately short and will stay that way until independent reporting says more about the cluster than ReliaQuest's single reference.