Empire Operations: Tactics (APT28)

Empire Operations: Tactics (APT28)

Empire Operations: Tactics (APT28) is an intermediate-level course focusing on executing APT Tactics, Techniques, and Procedures (TTPs) using Empire. Students will evaluate Fancy Bear’s 2021-2022 campaign, using MSHTML RCE (CVE-2021-40444), OneDrive C2, and C# payloads.

Emulate Fancy Bear with Empire

Study APT28 tradecraft and reproduce key 2021–2022 campaign techniques using Empire, from MSHTML (CVE-2021-40444) delivery to OneDrive-based C2.

Course Modules

Hands-on operator workflows to emulate APT28 TTPs in realistic lab environments.

Contact

Intro to Threat Emulation - Fancy Bear

Threat emulation basics, command and control theory, and overview of Fancy Bear and their TTPs.
Contact

Fancy Bear's Attack Infrastructure and Tools

Leveraging OneDrive as a C2, Office vulnerabilities, and segmenting architecture for operational security.
Contact

Exploiting the Target

.NET tradecraft, exploiting Outlook for profit and gain, DLL exploitation, and leveraging unmanaged code for use with .NET.
Work With Us

Ready to Test Your Defenses Against Real Threats?

Talk to BC Security about penetration testing, red team operations, or hands‑on training. We’ll map real adversary TTPs to your environment and help you make risk‑based decisions.

Veteran Owned & Operated

Founded and operated by U.S. military veterans bringing mission-focused discipline to cybersecurity

0000

Serving Clients Since

Offensive security assessments and training delivered since 2018.

00000 +

Community Members

Practitioners in the BC Security Discord community.