APT28__2025__CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF.pdf
ID: f951a358-15dc-4519-b0c1-fb13ee4786cc
STIX ID: report--f951a358-15dc-4519-b0c1-fb13ee4786cc
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2025-05-20
Last Modified Date: 2025-05-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This joint advisory describes sustained, state-sponsored cyber-espionage operations by Russia’s GRU unit 26165 (APT28/Fancy Bear) targeting Western logistics and technology companies involved in aid to Ukraine. The report documents initial-access methods (credential guessing, spearphishing, exploited CVEs such as CVE-2023-23397 and CVE-2023-38831, and SOHO device abuse), post-compromise activity (mailbox permission manipulation, lateral movement with Impacket/PsExec, RDP, NTDS dumping), malware (HEADLACE, MASEPIE, others), large-scale targeting of IP cameras for tracking shipments, detailed IOCs and YARA detections, and recommended mitigations mapped to MITRE ATT&CK and D3FEND frameworks.
