logo

Russian GRU Cyber Campaign Targets Western Logistics Firms Supporting Ukraine

ID: 140cbd87-f920-5363-a3d2-1dd9a3b43dcc

STIX ID: report--140cbd87-f920-5363-a3d2-1dd9a3b43dcc

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Samiksha Jain

...
...

A joint advisory attributes an active, ongoing Russian GRU Unit 26165 (APT28/Fancy Bear) cyber campaign—since early 2022—against logistics, transportation, and related IT service providers supporting Ukraine across multiple countries. The actors use spearphishing, credential attacks, CVE exploitation (notably CVE-2023-23397 and CVE-2023-38831), and malware (HEADLACE, MASEPIE) to gain persistence, exfiltrate shipment and operational data, and surveil movements via compromised IP cameras; recommended mitigations include enforcing MFA, patching, enhanced monitoring, and restricting partner trust relationships.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.