logo

Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units

ID: 14452752-6eac-401e-98dc-a7812d9fccda

STIX ID: report--14452752-6eac-401e-98dc-a7812d9fccda

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2017-07-27

Last Modified Date: 2017-07-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike details how FANCY BEAR (likely GRU) distributed an Android variant of its X-Agent remote access toolkit inside a trojanized D-30 artillery targeting app ('Понп-Д30.apk') used by Ukrainian forces; reverse engineering linked the APK to Windows X-Agent via protocol and cryptography, provided an MD5 indicator and a Snort rule for detection, and argued that the malware's collection of communications and location data likely enabled Russian forces to identify and target Ukrainian artillery units, contributing to significant equipment losses.