• News/
  • https://www.theregister.com/2025/05/21/russias_fancy_bear_alert/

Russia's Fancy Bear sticks its paws in transportation emails

The Register
·
Jessica Lyons
·
Published May 21, 2025
·
Updated

Russian cyberspies have targeted "dozens" of Western and NATO-country logistics providers, tech companies, and government orgs providing transport and foreign assistance to Ukraine, according to a joint government announcement issued Wednesday. The orgs they attacked span "virtually all transportation modes: air, sea, and rail," the security advisory [PDF] warns. And it points the finger at the Russian General Staff Main Intelligence Directorate (GRU) military unit 26165, aka APT28 or Fancy Bear. In addition to the logistics and technology entities, the GRU snoops targeted internet-connected cameras at Ukrainian border crossings to track aid shipments. "The actors also conducted reconnaissance on at least one entity involved in the production of industrial control system (ICS) components for railway management, though a successful compromise was not confirmed," the advisory notes. Twenty-one government agencies from the US, UK, Canada, Germany, France, Czech Republic, Poland, Austria, Denmark, and the Netherlands sounded the alarm, and said the campaign has been ongoing since 2022, which is when Russia first invaded neighboring Ukraine. The government bods' warning follows a similar alert from private research firm Eset last week about the same group of goons using spear phishing emails to target Ukrainian webmail servers that contain cross-site scripting vulnerabilities. To gain access to their victims, Fancy Bear employs its usual mix of credential guessing, spear-phishing,...

Read full article

Affected Software

6 affected components
Microsoft Exchange
Microsoft Outlook=CVE-2023-23397
Roundcube Roundcube=CVE-2020-12641
Roundcube Roundcube=CVE-2020-35730
Roundcube Roundcube=CVE-2021-44026
WinRAR WinRAR=CVE-2023-38831
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203