Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

One firm hedged, heise online named APT28

3 min read
12:09UTC

ReliaQuest put the hotel campaign's initial-access route at low-to-medium confidence and named no state actor. heise online reported on 27 July that Russian state attackers were behind it and named APT28.

TechnologyDeveloping
Key takeaway

One publisher named a state actor the researching firm would not; treat the label as contested.

ReliaQuest assessed the route by which the hotel routers were compromised at low-to-medium confidence, and said visibility constraints stopped it confirming that route at all 1. Its candidate explanation is exposed Secure Shell, Simple Network Management Protocol and web administration interfaces paired with weak or reused administrative credentials. ReliaQuest does not name APT28. What it reports instead is tradecraft reuse overlapping a cluster it tracks internally as FrostArmada, while stating that the current activity differs from prior FrostArmada activity in several respects.

heise online, the German technology publisher, described the same campaign on 27 July as the work of Russian state attackers and named APT28 directly 2. APT28, also tracked as Fancy Bear and as Unit 26165 of Russia's military intelligence service, carries roughly two decades of published state-attribution history, and attaching that label converts a vendor's hedged finding into a geopolitical fact. The two accounts cannot both be reported as they stand: heise online states as established what ReliaQuest explicitly declines to confirm, and this briefing takes neither side.

The machinery under the disagreement rewards attention. FrostArmada exists as a cluster label only inside ReliaQuest, so no other firm can corroborate or contradict the overlap it reports, and the hedge cannot be tested from outside. A state attribution repeated onward from secondary coverage can reach an insurer's act-of-war exclusion, a policy clause the underlying vendor assessment would not support, and it can do so without anyone rereading the original.

When Russia's FSB Centre 16 hijacked network-management protocols on internet gear, the naming came from NCSC alongside 18 partner agencies on 9 July , with governments putting their own credibility behind it. Nothing of that kind has been published about the hospitality campaign, and until it is, the codename in circulation traces back to one publisher rather than to the firm that did the research.

Deep Analysis

In plain English

When a cybersecurity firm investigates who is behind an attack, it doesn't always reach a confident answer, and when news outlets summarise that research, some of that uncertainty can get lost along the way. Here, the firm that actually found the hotel-router campaign, ReliaQuest, says it can only guess with 'low-to-medium confidence' at how the routers were first broken into, and it does not name the well-known Russian hacking group APT28 as responsible. It only says the campaign resembles, in a rough way, a different, less-known cluster it tracks under its own internal codename. A German technology outlet, heise online, reported the story on 27 July describing it as Russian state hackers and naming APT28 directly, a firmer claim than ReliaQuest's own report supports.

Deep Analysis
Root Causes

ReliaQuest's hedge traces to a specific gap: the firm states visibility constraints prevented it from confirming which of the exposed management interfaces, SSH, SNMP or web-admin, actually served as the entry point, and it can only report tradecraft overlap with a cluster it tracks under its own internal name, not the publicly known APT28 designation.

Secondary reporting compresses that hedge because 'Russian state hackers' is a simpler sentence than 'a firm citing low-to-medium confidence overlap with an internally labelled cluster that itself differs from prior activity'. The compression happens in translation, not in the underlying research.

What could happen next?
  • Meaning

    Readers following named-actor attribution in cyber reporting should treat secondary coverage as potentially firmer than the primary research it cites, particularly when the primary source itself uses hedged confidence language.

  • Risk

    If APT28 attribution later proves wrong, the correction burden falls on secondary coverage that went further than the source research, not on ReliaQuest's own hedged assessment.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

ReliaQuest· 3 Aug 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.