Lyce · Hybrid Watch

hw_23dacd7574ef7910

APT28 hack into SPD party’s systems, target executives.

The German authorities stated that the APT28 campaign began in late December 2022, when the Russian military intelligence-linked group targeted the SPD party headquarters. The attacks were part of a broader campaign that had been exploiting a vulnerability in Microsoft Outlook for Windows since at least March 2022, enabling the attackers to conduct cyberespionage. The campaign continued into 2023, targeting German organizations, including entities in the logistics, defence, aerospace and IT sectors. German authorities subsequently attributed the attacks to APT28 and Russia’s GRU, and said that the investigation had benefited from cooperation between German and international authorities as well as the affected organizations.

Occurrence
2022-12-25
Publication
2022-12-25T16:41:32Z
First observed
2026-09-30T16:30:48.138Z
Review status
Not assessed
Countries
DE
Updated
2026-10-02T16:30:09.889Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2022-12-25T16:41:32Z

    The German authorities stated that the APT28 campaign began in late December 2022, when the Russian military intelligence-linked group targeted the SPD party headquarters. The attacks were part of a broader campaign that had been exploiting a vulnerability in Microsoft Outlook for Windows since at least March 2022, enabling the attackers to conduct cyberespionage. The campaign continued into 2023, targeting German organizations, including entities in the logistics, defence, aerospace and IT sectors. German authorities subsequently attributed the attacks to APT28 and Russia’s GRU, and said that the investigation had benefited from cooperation between German and international authorities as well as the affected organizations.