>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…
Earlier news reports said they came to that conclusion by comparing the RAT artifacts on the compromised machines. ETA : Also, the bit.ly URLs used in the phishing attacks indicated sharing of resources with other APT28 hacks. http://motherboard.vice.com/read/how-hackers-broke-into-john...
For reference, this is the Podesta phishing email: https://wikileaks.org/podesta-emails/emailid/34899
And this is the stats page for the bit.ly link in that email: https://bitly.com/1PibSU0+