Site navigation

NCSC and Partners Expose Russian Cyber Campaign Targeting Ukraine

Elizabeth Greenberg

,

russia cyber ukraine
“This malicious campaign by Russia’s military intelligence service presents a serious risk to targeted organisations, including those involved in the delivery of assistance to Ukraine,” Paul Chichester, NCSC director of operations said.

An investigation from the National Cyber Security Centre (NCSC) and international allies has exposed a a malicious cyber campaign from the Russian military intelligence service targeting logistics entities and technology companies in Ukraine and its allies

The NCSC and partners from ten countries have revealed details about how military unit 26265 of Russia’s GRY have conducted an ongoing cyber campaign against both public and private organisations since 2022.

This has included targeting of organisations involved in the co-ordination, transport, and delivery of support to Ukraine, and across the defence, IT services, maritime, airports, ports, and air traffic management systems sectors in multiple NATO members.

Unit 26165 – also known as APT 28 or Fancy Bear – was able to gain initial access to victim networks using a mix of previously disclosed techniques, including credential guessing, spear-phishing and exploitation of Microsoft Exchange mailbox permissions.

They also targeted internet-connected cameras at Ukrainian border crossings and near military installations to monitor and track aid shipments to Ukraine.

The Russian hacking unit is known to have played a role in the cyber-attack on the US Democratic National Committee in 2016, as well as a date leak from the World Anti-Doping Agency.

“This malicious campaign by Russia’s military intelligence service presents a serious risk to targeted organisations, including those involved in the delivery of assistance to Ukraine,” Paul Chichester, NCSC director of operations said.

“The UK and partners are committed to raising awareness of the tactics being deployed.

“We strongly encourage organisations to familiarise themselves with the threat and mitigation advice included in the advisory to help defend their networks.”


Recommended reading


The NCSC is urging executives and network defenders at technology and logistics companies should recognise the elevated threat of targeting and take immediate protective action.

This would include increasing monitoring, using multi-factor authentication with strong factors – such as passkeys – and ensuring security updates are applied promptly to manage vulnerabilities.

The NCSC has co-sealed this advisory alongside agencies from the United States, Germany, Czech Republic, Poland, Australia, Canada, Denmark, Estonia, France and the Netherlands.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data