CISA: Russia's Fancy Bear Targeting Logistics, IT Firms
ID: dafacb36-e5af-500c-a24c-8accf720d6b5
STIX ID: report--dafacb36-e5af-500c-a24c-8accf720d6b5
Feed Name: Dark Reading
Fancy Bear (APT28), a Russia-linked state-backed actor, is conducting an active cyber-espionage campaign against Western logistics, transportation, and IT firms (notably those aiding Ukraine). The campaign uses spear-phishing, credential-guessing, and exploitation of multiple vulnerabilities (e.g., CVE-2023-23397, WinRAR CVE-2023-38831, Roundcube CVEs) to gain initial access, deploy malware such as Xagent, move laterally with legitimate tools (Impacket, PsExec, RDP), compromise assets including IP cameras, and exfiltrate data; CISA and international partners published IOCs and recommended mitigations including segmentation, logging, EDR, and blocking public VPN logins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
