Russian cyberspies have targeted "dozens" of Western and NATO-country logistics providers, tech companies, and government orgs providing transport and foreign assistance to Ukraine, according to a joint government announcement issued Wednesday. The orgs they attacked span "virtually all transportation modes: air, sea, and rail," the security advisory [PDF] warns. And it points the finger at the Russian General Staff Main Intelligence Directorate (GRU) military unit 26165, aka APT28 or Fancy Bear. In addition to the logistics and technology entities, the GRU snoops targeted internet-connected cameras at Ukrainian border crossings to track aid shipments. "The actors also conducted reconnaissance on at least one entity involved in the production of industrial control system (ICS) components for railway management, though a successful compromise was not confirmed," the advisory notes. Twenty-one government agencies from the US, UK, Canada, Germany, France, Czech Republic, Poland, Austria, Denmark, and the Netherlands sounded the alarm, and said the campaign has been ongoing since 2022, which is when Russia first invaded neighboring Ukraine. The government bods' warning follows a similar alert from private research firm Eset last week about the same group of goons using spear phishing emails to target Ukrainian webmail servers that contain cross-site scripting vulnerabilities. To gain access to their victims, Fancy Bear employs its usual mix of credential guessing, spear-phishing,...
Russia's Fancy Bear sticks its paws in transportation emails
The Register
·Jessica Lyons
·Published May 21, 2025
·Updated
Affected Software
6 affected components
Microsoft Exchange
Microsoft Outlook=CVE-2023-23397
Roundcube Roundcube=CVE-2020-12641
Roundcube Roundcube=CVE-2020-35730
Roundcube Roundcube=CVE-2021-44026
WinRAR WinRAR=CVE-2023-38831