APT28__2016__Crowdstrike_FancyBearTracksUkrainianArtillery_12-22-2016.pdf
ID: 4a8ad80b-87b0-4c68-a888-b6ffa9264c04
STIX ID: report--4a8ad80b-87b0-4c68-a888-b6ffa9264c04
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-12-21
Last Modified Date: 2016-12-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike describes discovery of a FANCY BEAR X-Agent Android variant embedded in a legitimate Ukrainian D-30 howitzer targeting app (Попр-Д30.apk); the malware exfiltrated contacts, SMS, call logs, internet data and coarse location to support reconnaissance of artillery units, and CrowdStrike assesses it as a GRU-linked, targeted nation-state campaign that expanded Russian mobile malware capabilities on the battlefield.
