Russian GRU Cyber Campaign Targets Western Logistics Firms Supporting Ukraine
ID: 140cbd87-f920-5363-a3d2-1dd9a3b43dcc
STIX ID: report--140cbd87-f920-5363-a3d2-1dd9a3b43dcc
Feed Name: The Cyber Express
A joint advisory attributes an active, ongoing Russian GRU Unit 26165 (APT28/Fancy Bear) cyber campaign—since early 2022—against logistics, transportation, and related IT service providers supporting Ukraine across multiple countries. The actors use spearphishing, credential attacks, CVE exploitation (notably CVE-2023-23397 and CVE-2023-38831), and malware (HEADLACE, MASEPIE) to gain persistence, exfiltrate shipment and operational data, and surveil movements via compromised IP cameras; recommended mitigations include enforcing MFA, patching, enhanced monitoring, and restricting partner trust relationships.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
