ReliaQuest assessed the route by which the hotel routers were compromised at low-to-medium confidence, and said visibility constraints stopped it confirming that route at all 1. Its candidate explanation is exposed Secure Shell, Simple Network Management Protocol and web administration interfaces paired with weak or reused administrative credentials. ReliaQuest does not name APT28. What it reports instead is tradecraft reuse overlapping a cluster it tracks internally as FrostArmada, while stating that the current activity differs from prior FrostArmada activity in several respects.
heise online, the German technology publisher, described the same campaign on 27 July as the work of Russian state attackers and named APT28 directly 2. APT28, also tracked as Fancy Bear and as Unit 26165 of Russia's military intelligence service, carries roughly two decades of published state-attribution history, and attaching that label converts a vendor's hedged finding into a geopolitical fact. The two accounts cannot both be reported as they stand: heise online states as established what ReliaQuest explicitly declines to confirm, and this briefing takes neither side.
The machinery under the disagreement rewards attention. FrostArmada exists as a cluster label only inside ReliaQuest, so no other firm can corroborate or contradict the overlap it reports, and the hedge cannot be tested from outside. A state attribution repeated onward from secondary coverage can reach an insurer's act-of-war exclusion, a policy clause the underlying vendor assessment would not support, and it can do so without anyone rereading the original.
When Russia's FSB Centre 16 hijacked network-management protocols on internet gear, the naming came from NCSC alongside 18 partner agencies on 9 July , with governments putting their own credibility behind it. Nothing of that kind has been published about the hospitality campaign, and until it is, the codename in circulation traces back to one publisher rather than to the firm that did the research.
