According to Kaspersky, the Sofacy APT is particularly interested in military, defense and diplomatic entities in the far east. The Russian APT groups activity overlaps with cyber espionage campaigns conducted by other threat actors. Sofacy SPLM malware has infected the same systems that were compromised by Danti China-linked APT. At least a server belonging to a military and aerospace conglomerate in China was infected by Sofacy backdoors and Longhorn malware. The researchers noticed that the overlaps were frequent on systems belonging to government, technology and military organizations in Central Asia.”]
Source: https://securityaffairs.co/wordpress/70129/apt/sofacy-apt-operations.html