Fancy Bear threat group
Fancy Bear, also known as the Sofacy threat group, is a Kremlin-based cyber-espionage group. The threat group’s other names include APT28, Strontium, Tsar Team, and Pawn Storm. Fancy Bear primarily targets government entities, defense, energy, and media sectors.
Sofacy’s major attacks
Sofacy aka Fancy Bear is said to be responsible for various attacks on the following:
Venomous Bear threat group
Venomous Bear, better known as Turla threat group is a Russian-based cyber-espionage group. This threat group is also known as Snake, Group 88, Waterbug, WRAITH, Uroburos, Pfinet, TAG_0530, KRYPTON, Hippo Team, Pacifier APT, Popeye, SIG23, and Iron Hunter. Venomous Bear primarily targets the government, militaries, and embassies.
Turla’s major attacks
Malicious tools used by the groups
Fancy Bear widely uses malware such as ADVSTORESHELL, CHOPSTICK, JHUHUGIT, and XTunnel. The group has also developed several custom malware such as Foozer, WinIDS, X-Agent, X-Tunnel, and DownRange.
On the other hand, the Turla APT group has been known to use malicious tools such as Gazer, KopiLuwak, ICEDCOFFEE, Carbon backdoor, Moonlight Maze, Mosquito backdoor, Mimikatz, Outlook backdoor, and LightNeuron backdoor.
While both the threat groups are cyber-espionage groups primarily targeting government entities, their attack vectors, targets, and the malware used differs
Publisher