Western intelligence agencies unite to expose Russian hacking campaign against logistics and tech firms
俄罗斯军事情报机构旗下的黑客组织Fancy Bear被指对多国物流和技术公司发动网络攻击,目标包括政府和私营部门的运输系统及监控设施。此次行动由11国及21个情报机构联合发布警告,呼吁加强网络安全防御。 2025-5-21 15:1:31 Author: therecord.media(查看原文) 阅读量:4 收藏

A notorious Russian hacking unit was blamed on Wednesday for conducting a widespread campaign that officials say “presents a serious risk” to the targeted organizations and sectors in more than a dozen countries.

In a joint cybersecurity advisory co-sealed by what appears to be a record number of allied countries (11) and intelligence agencies (21), the hacking group widely known as Fancy Bear or APT28 was accused of being behind attempted digital break-ins at multiple Western logistics providers and technology firms.

“Dozens of entities, including government organizations and private/commercial entities across virtually all transportation modes: air, sea, and rail” have been targeted in the campaign within NATO member states, within Ukraine, and at international organisations, according to the advisory.

Alongside the “espionage-oriented campaign” the hackers are also believed to have accessed legitimate municipal traffic cams as well as “private cameras at key locations, such as near border crossings, military installations, and rail stations, to track the movement of materials into Ukraine.”

The hackers also “conducted reconnaissance on at least one entity involved in the production of industrial control system components for railway management, though a successful compromise was not confirmed,” warned the advisory.

The intelligence agencies formally attributed the attacks to the “85th Main Special Service Center (85th GTsSS), military unit 26165” of Russia’s military intelligence agency, the GRU, and acknowledged the hacking unit’s campaigns were tracked under a number of names, including Fancy Bear and APT 24.

Although the campaign did not utilize any novel techniques — with the hackers described as gaining initial access to their victims’ networks by “using a mix of previously disclosed techniques, including credential guessing, spear-phishing and exploitation of Microsoft Exchange mailbox permissions” — the widespread nature of the campaign has prompted the advisory encouraging potential victims to shore up their defenses.

Paul Chichester, the director of operations at Britain’s National Cyber Security Centre (NCSC) said: “This malicious campaign by Russia’s military intelligence service presents a serious risk to targeted organisations, including those involved in the delivery of assistance to Ukraine.

“The UK and partners are committed to raising awareness of the tactics being deployed. We strongly encourage organisations to familiarise themselves with the threat and mitigation advice included in the advisory to help defend their networks,” added Chichester.

The NCSC said that both executives at technology and logistics companies, as well as network defenders, needed to recognise the elevated threat of targeting “and take immediate action to protect themselves.”

Agencies from the U.K., U.S., Germany, France, Canada, Czechia, Poland, Australia, Estonia, Denmark and the Netherlands co-signed the advisory.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.


文章来源: https://therecord.media/western-intelligence-alert-russia-hackers-logistics-fancy-bear-apt28
如有侵权请联系:admin#unsafe.sh