Q. Which of the following Advanced Persistent Threat (APT) group is said to be connected to the Russian Armed Forces main military intelligence wing?
Answer:
Strontium
Notes:
- Strontium is also known as Fancy Bear, Tsar Team, Pawn Storm, Sofacy, Sednit or Advanced Persistent Threat 28 (APT28) group. It is a highly active and prolific cyber-espionage group. It is one of the most active APT groups and has been operating since at least the mid-2000s. The group is said to be connected to the GRU, the Russian Armed Forces’ main military intelligence wing. The group deploys diverse malware and malicious tools to breach networks. In the past, it has used X-Tunnel, SPLM (or CHOPSTICK and X-Agent), GAMEFISH and Zebrocy to attack targets.
- Lazarus Group has been tied to the North Korean government’s Reconnaissance General Bureau (RGB). One of the attacks that they are best known for was the retaliatory attack on Sony in 2014. It has now been designated as an advanced persistent threat due to intended nature, threat, and wide array of methods used when conducting an operation.
- The Equation Group (also known as Shadow Brokers) is potentially connected to the US National security Agency. A notable attack they’re likely tied to took place 2010 and targeted Iran’s nuclear program.
- Machete is a South American group that has been extremely hard to track. They are likely to be based in Venezuela. They use advanced phishing tactics to gain access and steal large amounts of sensitive data.