Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

One firm hedged, heise online named APT28

3 min read
16:08UTC

ReliaQuest put the hotel campaign's initial-access route at low-to-medium confidence and named no state actor. heise online reported on 27 July that Russian state attackers were behind it and named APT28.

TechnologyDeveloping
Key takeaway

One publisher named a state actor the researching firm would not; treat the label as contested.

ReliaQuest assessed the route by which the hotel routers were compromised at low-to-medium confidence, and said visibility constraints stopped it confirming that route at all 1. Its candidate explanation is exposed Secure Shell, Simple Network Management Protocol and web administration interfaces paired with weak or reused administrative credentials. ReliaQuest does not name APT28. What it reports instead is tradecraft reuse overlapping a cluster it tracks internally as FrostArmada, while stating that the current activity differs from prior FrostArmada activity in several respects.

heise online, the German technology publisher, described the same campaign on 27 July as the work of Russian state attackers and named APT28 directly 2. APT28, also tracked as Fancy Bear and as Unit 26165 of Russia's military intelligence service, carries roughly two decades of published state-attribution history, and attaching that label converts a vendor's hedged finding into a geopolitical fact. The two accounts cannot both be reported as they stand: heise online states as established what ReliaQuest explicitly declines to confirm, and this briefing takes neither side.

The machinery under the disagreement rewards attention. FrostArmada exists as a cluster label only inside ReliaQuest, so no other firm can corroborate or contradict the overlap it reports, and the hedge cannot be tested from outside. A state attribution repeated onward from secondary coverage can reach an insurer's act-of-war exclusion, a policy clause the underlying vendor assessment would not support, and it can do so without anyone rereading the original.

When Russia's FSB Centre 16 hijacked network-management protocols on internet gear, the naming came from NCSC alongside 18 partner agencies on 9 July , with governments putting their own credibility behind it. Nothing of that kind has been published about the hospitality campaign, and until it is, the codename in circulation traces back to one publisher rather than to the firm that did the research.

Deep Analysis

In plain English

When a cybersecurity firm investigates who is behind an attack, it doesn't always reach a confident answer, and when news outlets summarise that research, some of that uncertainty can get lost along the way. Here, the firm that actually found the hotel-router campaign, ReliaQuest, says it can only guess with 'low-to-medium confidence' at how the routers were first broken into, and it does not name the well-known Russian hacking group APT28 as responsible. It only says the campaign resembles, in a rough way, a different, less-known cluster it tracks under its own internal codename. A German technology outlet, heise online, reported the story on 27 July describing it as Russian state hackers and naming APT28 directly, a firmer claim than ReliaQuest's own report supports.

Deep Analysis
Root Causes

ReliaQuest's hedge traces to a specific gap: the firm states visibility constraints prevented it from confirming which of the exposed management interfaces, SSH, SNMP or web-admin, actually served as the entry point, and it can only report tradecraft overlap with a cluster it tracks under its own internal name, not the publicly known APT28 designation.

Secondary reporting compresses that hedge because 'Russian state hackers' is a simpler sentence than 'a firm citing low-to-medium confidence overlap with an internally labelled cluster that itself differs from prior activity'. The compression happens in translation, not in the underlying research.

What could happen next?
  • Meaning

    Readers following named-actor attribution in cyber reporting should treat secondary coverage as potentially firmer than the primary research it cites, particularly when the primary source itself uses hedged confidence language.

  • Risk

    If APT28 attribution later proves wrong, the correction burden falls on secondary coverage that went further than the source research, not on ReliaQuest's own hedged assessment.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

ReliaQuest· 3 Aug 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.