Skip to content
Flash Briefing high Government

APT28 Intensifies Targeting of European Government Networks Ahead of 2026 Election Cycle

The access gets established months before anyone votes. That’s the pattern, and APT28 has been running it across European governments without significant variation since at least 2016.

Multiple European national CERTs and Microsoft’s Threat Intelligence Centre have identified elevated APT28 activity across European government networks through the first half of 2026. The group, assessed with high confidence to operate under GRU direction, has registered new credential-harvesting infrastructure and refined its spear-phishing lure set to target ministerial staff, parliamentary researchers, and NATO working group members. Lure themes track live European policy debates: energy security, defence procurement, EU institutional processes. The targeting is narrow and clearly researched. Recipients are individuals whose public roles connect directly to the subject matter of the lure.

What This Campaign Is Deploying

APT28 is running two parallel tracks in current operations.

Credential harvesting through lookalike domains. The group has registered a cluster of domains mimicking European government SSO portals and NATO Outlook Web Access interfaces. Victims directed to these pages are prompted to re-authenticate. Those credentials are then used against genuine government systems, often not immediately, which is part of the problem. Access established today may sit dormant for months.

MASEPIE and OCEANMAP backdoors for recipients who execute lure attachments. MASEPIE is a Python-based backdoor that uses IMAP over port 993 for command-and-control, a channel that most perimeter monitoring doesn’t flag because IMAPS is a legitimate protocol. OCEANMAP is a .NET backdoor, also attributed to APT28 in late 2023 Ukrainian targeting, now appearing in broader European government campaigns. The combination gives the actor persistent access with a C2 path that blends with normal email traffic.

The Election Collection Timeline

This is how the APT28 electoral playbook works: access is established during the pre-campaign period, data is collected at scale, and leaks are timed for maximum disruption at a politically sensitive moment, not necessarily during the intrusion, but weeks or months later when the impact is greatest.

The 2016 En Marche leaks ahead of the French presidential election. The Bundestag intrusion in 2017. The CDU systems targeting in 2024. Different targets, same architecture. Collect first, deploy later. The group has demonstrated the patience to sit on material until the moment maximises damage.

With significant electoral events across EU member states and the UK scheduled through 2026, the current targeting posture is consistent with preparation, not immediate disruption. The question isn’t whether APT28 is collecting data from European governments right now. It almost certainly is. The question is what gets released, and when.

What Defenders Can Actually Do

Generic phishing awareness training doesn’t move the needle here. APT28 lures are precisely researched, topically relevant, and sent to individuals whose responsibility for the subject matter makes them plausible recipients of the communication. A security awareness briefing about not clicking suspicious links is not the answer.

What actually matters:

Brief ministerial and senior staff on the specific lure themes in active circulation: energy security, defence procurement, EU affairs. The briefing needs to be current and specific, not a recycled awareness deck.

Phishing-resistant MFA. MASEPIE and OCEANMAP only persist if initial access succeeds, whether through credential theft or code execution. Hardware keys or passkeys eliminate the credential-harvesting path entirely. This is the highest-leverage single control against the current campaign.

IMAPS egress from workstations shouldn’t be routine. Monitoring and restricting outbound connections on port 993 from endpoints (not from mail servers, from workstations) is a meaningful and specific detection control for MASEPIE’s C2 channel. Most environments don’t have this in place.

Lookalike domain monitoring for your SSO and OWA infrastructure is basic but underdeployed. NCSC’s Check Your Cyber capability covers this. If you don’t have visibility over domain registrations impersonating your organisation’s authentication portals, you won’t see the phishing infrastructure until someone gets hit.