Netskope Threat Labs

FancyBear

ATP Sandbox Adv. HeuristicsAV

FancyBear refers to detections associated with Fancy Bear (APT28), a Russian state sponsored threat group known for espionage against governments, militaries, and critical infrastructure. The group has operated since at least the mid 2000s and conducts phishing, credential harvesting, and exploitation of software vulnerabilities to maintain persistent access.

First seen
June 2025
Last seen
October 2026
Alert Name
Binary.Malware.FancyBear
ByteCode-MSIL.Trojan.FancyBear
Dump:Generic.PY.FancyBear.B.FFFFFFFE
Generic.PY.FancyBear.A.00EF8EC5
Generic.PY.FancyBear.A.03DFB376
Generic.PY.FancyBear.A.07CE2326
Generic.PY.FancyBear.A.08EB8B8D
Generic.PY.FancyBear.A.0D8E6283
Generic.PY.FancyBear.A.0D978974
Generic.PY.FancyBear.A.0F464B2F