Overview
- A joint advisory from the US, UK, and nine other nations attributes a sustained cyber campaign to Russia’s GRU Unit 26165, also known as Fancy Bear or APT28.
- The campaign, active since February 2022, targets organizations in defense, transport, maritime, air traffic, and IT sectors aiding Ukraine.
- Hackers used tactics such as credential guessing, spear-phishing, and Microsoft Exchange exploits to infiltrate networks and monitor aid shipments.
- Thousands of internet-connected cameras at Ukrainian border crossings and key locations were compromised to track aid movements.
- Organizations are urged to implement multi-factor authentication, patch vulnerabilities, and enhance monitoring to mitigate ongoing threats.