Russian APTs Treat Red Team Research as a Playbook
The GRU, SVR, and FSB do not build novel techniques from scratch. They watch offensive security publications, identify methods their targets use, and plug them into active campaigns. Will Thomas spent three and a half years tracking this pattern at Equinix, the world’s largest data center company, observing APT28, APT29, and Turla adopt techniques from public red team blogs within days of release. Attribution reports often surface years after the technique was already public, so waiting for one means running detections years too late.
Device Code Phishing and RDP Config Files: Two Years of Free Access
Black Hills published the M365 device code phishing technique in 2023. SVR used it against US and European governments and NGOs in early 2025, sending lures through WhatsApp, Signal, Element, and Teams that asked targets to submit a device login code. One code hands over full M365 access. The same organization had disclosed RDP config file delivery in February 2022. APT28 was sending RDP files as email attachments to Ukrainian, UK, and US government targets by October 2024. Neither campaign required custom malware or zero-day exploits.
Azure AD and TeamCity: Speed of Adoption After Public Disclosure
Secureworks and Tenable disclosed a bug in Azure AD that allowed unlimited password spraying with no rate limiting. SVR exploited it for years, using residential proxies and Tor exit nodes to keep requests as slow as one per hour. Attribution took years. In October 2023, Rapid7 published a TeamCity proof-of-concept after responsible disclosure. SVR had it within a week and started hitting government organizations. Both cases show the same pattern: public research drops, attribution arrives years later.
Teams Phishing and HTML Smuggling: Abusing Legitimate Channels
SVR targeted foreign ministries, military agencies, and governments involved with the Ukraine war by abusing Microsoft Teams external tenant messaging. An attacker from a spoofed or freshly created tenant sends a message, the target enters a code, and the account is compromised. HTML smuggling had been in red team documentation since 2018, but APT29 ran campaigns using it in May 2021. The payload: an HTML attachment decodes to an ISO file, mounts silently, uses DLL sideloading through Acrobat, and drops malware while showing the user a decoy PDF.
ClickFix and the Russian APT Tool Matrix
John Hammond published ClickFix on GitHub in September 2024 after observing threat actors test the method. It presents users with a fake CAPTCHA, instructs them to press Windows+R, and pastes a pre-staged script from the clipboard. Ukrainian authorities observed APT28 using it for spearfishing shortly after release. To track what all three Russian APT groups carry into campaigns, Thomas built the Russian APT Tool Matrix on GitHub. It catalogs credential theft tools, EDR disablers, and C2 frameworks including Cobalt Strike, Sliver, and Brute Ratel C4, the latter obtained through cracked copies on underground forums.
Notable Quotes
there was no rate limiting whatsoever. Will Thomas · ▶ 9:37
campaigns. It’s not that sophisticated. Will Thomas · ▶ 8:09
you’re like hold up what’s going on here Will Thomas · ▶ 16:47
Key Takeaways
- APT28, APT29, and Turla all adopted techniques from public red team blogs, sometimes within days of publication.
- Building detections when research drops gives defenders coverage before any APT weaponizes the technique.
- SVR and APT28 favor Teams, M365, and Azure AD because legitimate infrastructure is harder to block wholesale.
- The Russian APT Tool Matrix on GitHub lists reused tools per group, a concrete detection starting point.
About the Speaker(s)
Will Thomas is a Senior Threat Intel Advisor at Team Cymru. Previously he worked as a CTI Researcher and Threat Hunter at the Equinix Threat Analysis Center, and before that at Cyjax, a UK-based CTI vendor. He is co-author of the SANS FOR589: Cybercrime Intelligence course, co-founder of the Curated Intelligence trust group, and organizer of Bournemouth 2600.