APT28
""It's the worst thing that can happen to you in television," Mr Bigot told me in his Paris office.
It quickly became clear that the network had been subject to a serious cyber-attack.
"We were a couple of hours from having the whole station gone for good."
Screens went blank in the foyer of TV5Monde.
It was a race against time - more systems were corrupted with every passing minute. Any substantial delay would have led satellite distribution channels to cancel their contracts, placing the entire company in jeopardy.
"We were saved from total destruction by the fact we had launched the channel that day and the technicians were there," said Mr Bigot.
"One of them was able to locate the very machine where the attack was taking place and he was able to cut out this machine from the internet and it stopped the attack."
"We owe a lot to the engineer who unplugged that particular machine. He is a hero here," Mr Bigot said.
The attack was far more sophisticated and targeted than reported at the time. The perpetrators had first penetrated the network on 23 January.
They carried out reconnaissance of TV5Monde to understand the way in which it broadcast its signals. They then fabricated bespoke malicious software to corrupt and destroy the internet-connected hardware that controlled the TV station's operations - such as the encoder systems used to transmit programmes."
Mr Bigot was later told evidence had been found that his network had been attacked by a group of Russian hackers, who are known as APT 28.
http://www.bbc.com/news/technology-37590375