Russian GRU Targeting Western Logistics Entities and Technology Companies
ID: 38dc7c11-059b-5929-af69-a6cc7bfab1d9
STIX ID: report--38dc7c11-059b-5929-af69-a6cc7bfab1d9
Feed Name: CISA Cybersecurity Advisories
**Executive Summary:** This joint advisory attributes a persistent Russian GRU (unit 26165 / APT28) campaign against Western logistics and technology firms—particularly those supporting aid to Ukraine—detailing spearphishing and credential-guessing initial access, exploitation of multiple CVEs (including CVE-2023-23397 and CVE-2023-38831), deployment of malware (e.g., HEADLACE, MASEPIE, STEELHOOK), mailbox-permission abuse for sustained email collection, lateral movement and AD targeting, large-scale targeting of IP cameras for tracking shipments, and extensive IOCs and mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
