logo

APT28__2016__Crowdstrike_FancyBearTracksUkrainianArtillery_12-22-2016.pdf

ID: 4a8ad80b-87b0-4c68-a888-b6ffa9264c04

STIX ID: report--4a8ad80b-87b0-4c68-a888-b6ffa9264c04

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-12-21

Last Modified Date: 2016-12-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike describes discovery of a FANCY BEAR X-Agent Android variant embedded in a legitimate Ukrainian D-30 howitzer targeting app (Попр-Д30.apk); the malware exfiltrated contacts, SMS, call logs, internet data and coarse location to support reconnaissance of artillery units, and CrowdStrike assesses it as a GRU-linked, targeted nation-state campaign that expanded Russian mobile malware capabilities on the battlefield.