logo

CISA: Russia's Fancy Bear Targeting Logistics, IT Firms

ID: dafacb36-e5af-500c-a24c-8accf720d6b5

STIX ID: report--dafacb36-e5af-500c-a24c-8accf720d6b5

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-05-22

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Fancy Bear (APT28), a Russia-linked state-backed actor, is conducting an active cyber-espionage campaign against Western logistics, transportation, and IT firms (notably those aiding Ukraine). The campaign uses spear-phishing, credential-guessing, and exploitation of multiple vulnerabilities (e.g., CVE-2023-23397, WinRAR CVE-2023-38831, Roundcube CVEs) to gain initial access, deploy malware such as Xagent, move laterally with legitimate tools (Impacket, PsExec, RDP), compromise assets including IP cameras, and exfiltrate data; CISA and international partners published IOCs and recommended mitigations including segmentation, logging, EDR, and blocking public VPN logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.