Cyber Historical (last time active at 28.02.2022 05:16:44)
Listed (1)
23.10.2020
Names (11)
Last name/Name
85th Main Special Service Centre (GTsSS)
Full name/Name
85th Main Special Service Centre (GTsSS)
Type
Primary name
Last name/Name
GRU Unit 26165
Full name/Name
GRU Unit 26165
Type
Primary name variation
Last name/Name
Pawn Storm
Full name/Name
Pawn Storm
Type
AKA (also known as)
Last name/Name
Iron Twilight
Full name/Name
Iron Twilight
Type
AKA (also known as)
Last name/Name
Sednit
Full name/Name
Sednit
Type
AKA (also known as)
Last name/Name
Sofacy Group
Full name/Name
Sofacy Group
Type
AKA (also known as)
Last name/Name
Tsar Team
Full name/Name
Tsar Team
Type
AKA (also known as)
Last name/Name
Threat Group-4127/Iron Twilight
Full name/Name
Threat Group-4127/Iron Twilight
Type
AKA (also known as)
Last name/Name
APT28 (Advanced Persistent Threat)
Full name/Name
APT28 (Advanced Persistent Threat)
Type
AKA (also known as)
Last name/Name
FANCY BEAR
Full name/Name
FANCY BEAR
Type
AKA (also known as)
Last name/Name
STRONTIUM
Full name/Name
STRONTIUM
Type
AKA (also known as)
Addresses (1)
Country
Russian Federation
Postal code
1
Identification documents (2)
Type
Entity Type: Department within Government
Type
Entity Parent Company: Russian Ministry of Defence
Notes (3)
The 85th Main Centre for Special Technologies (GTsSS) of the Russian General Staff of the Armed Forces of the Russian Federation (GRU) - also known by its field post number ‘26165’ and industry nicknames: APT28, Fancy Bear, Sofacy Group, Pawn Storm, Strontium - was involved in illegally accessing the information systems of the German Federal Parliament (Deutscher Bundestag) without permission in April and May 2015.The military intelligence officers of the 85th controlled, directed and took part in this activity, accessing the email accounts of MPs and stealing their data. Their activity interfered with the parliament’s information systems affecting its operation for several days, undermining the exercise of parliamentary functions in Germany.
The 85th Main Centre for Special Technologies (GTsSS) of the Russian General Staff of the Armed Forces of the Russian Federation (GRU) - also known by its field post number ‘26165’ and industry nicknames: APT28, Fancy Bear, Sofacy Group, Pawn Storm, Strontium - was involved in illegally accessing the information systems of the German Federal Parliament (Deutscher Bundestag) without permission in April and May 2015. The military intelligence officers of the 85th controlled, directed and took part in this activity, accessing the email accounts of MPs and stealing their data. Their activity interfered with the parliament’s information systems affecting its operation for several days, undermining the exercise of parliamentary functions in Germany.
The 85th Main Special Services Centre (GTsSS) (Unit 26165) of the Russian General Staff of the Armed Forces of the Russian Federation (GRU), is involved in relevant cyber activity in that it has been responsible for, engaging in, providing support for, or promoting the commission, planning or preparation or relevant cyber activity, including the deployment of X-Agent malware. These activities undermine, or are intended to undermine, the integrity, prosperity or security of the United Kingdom or a country other than the United Kingdom.
Historical data
Names (13)
Status
Historical (last time active at 28.02.2022 05:16)
Last name/Name
GRU 85th Main Special Service Centre (GTsSS) (APT 28)
Full name/Name
GRU 85th Main Special Service Centre (GTsSS) (APT 28)
Type
Prime alias
Status
Historical (last time active at 18.07.2025 14:15)
Last name/Name
GRU 85th Main Special Service Centre (GTsSS) (APT 28)
Full name/Name
GRU 85th Main Special Service Centre (GTsSS) (APT 28)
Updated: 04.11.2025. 11:16
Sanctions list data updated: 19.09.2025. 16:15
The Sanction catalog includes Latvian, United Nations, European Union, United Kingdom and Office of Foreign Assets Control and Canada subjects included in sanction list.