I think I might have missed it, but how did they conclude that it was 'APT28' ?
> APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.
Aren't these standard phishing 101 techniques. What makes them specific to 'APT28'. This 'report' looks like someone googled 'phishing 101' and 'web security 101' and copy pasted bunch of stuff from wikipedia.