Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecritical-infrastructure-threatgovernment-diplomatic-threatinitial-access-method

Russian GRU Targets Western Logistics and Defense Supply Chains for Ukraine Intelligence

Updated 28d agoFirst seen Apr 17, 20264 sources

A joint government advisory says Russia’s GRU Unit 26165, also tracked as APT28 or Fancy Bear, has run a sustained cyberespionage campaign against Western logistics providers, technology companies, and defense supply-chain organizations supporting aid flows to Ukraine. The activity has affected entities in the United States, Germany, Poland, France, and Ukraine, with intrusions aimed at transportation networks, IT services, and military-related logistics. Officials said the operators also sought visibility into aid movements by compromising internet-connected IP cameras positioned near border crossings, rail hubs, and military facilities.

Authorities linked the campaign to long-running GRU tradecraft previously used against governments, militaries, defense contractors, and cloud and email environments including Microsoft Office 365 and on-premises Exchange. Reported access methods include password spraying, brute-force and credential-guessing attacks, spearphishing, exploitation of known vulnerabilities including CVE-2020-0688 and CVE-2020-17144, and the use of malware such as HEADLACE and MASEPIE, alongside web shells, Tor, VPNs, and living-off-the-land techniques to persist and exfiltrate data. Agencies warned the espionage effort remains active and urged organizations to enforce MFA, patch exposed systems, tighten access controls, monitor for lateral movement, and review supply-chain risk.

Share:
Russian GRU Targets Western Logistics and Defense Supply Chains for Ukraine Intelligence
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
May 21, 20251y ago

Joint advisory warns of ongoing GRU campaign against logistics sector

A joint cybersecurity advisory disclosed the ongoing GRU campaign against Western logistics and technology organizations supporting aid flows to Ukraine, including the use of credential attacks, spearphishing, exploitation of known vulnerabilities, and malware such as HEADLACE and MASEPIE. The advisory also warned that the actors were targeting internet-connected IP cameras near border crossings, rail stations, and military facilities to monitor aid movements.

Feb 24, 20224y ago

Russian GRU begins targeting Western logistics and tech firms aiding Ukraine

A cyber campaign attributed to Russian GRU Unit 26165 (APT28/Fancy Bear) began targeting Western logistics entities and technology companies involved in coordinating, transporting, and delivering foreign assistance to Ukraine. The activity also affected transportation, IT services, and defense industrial base organizations in multiple countries.

Jul 1, 20215y ago

US and UK disclose global GRU cyberespionage campaign

The United States and United Kingdom publicly warned of a Russian cyberespionage campaign targeting hundreds of organizations worldwide, especially US and European governments, militaries, and defense contractors. A joint advisory attributed the activity to GRU Unit 26165/APT28 and described attacks on Microsoft Office 365 and on-premises Exchange using password spraying, brute force, and exploitation of CVE-2020-0688 and CVE-2020-17144.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Malware
2 linked
Affected products
2 linked
Roundcube WebmailWinrar
Organizations
2 linked
Microsoft CorporationThe Cyber Express
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.