Revealed: How Russian Hackers Infiltrate Ukraine Aid Networks Through Email and VPN Flaws


# Russian Cyber Espionage Campaign Targets Western Logistics and Tech Companies

Russian state-sponsored threat actor APT28 (also known as BlueDelta, Fancy Bear, or Forest Blizzard) has been conducting a sophisticated cyber espionage campaign against Western logistics entities and technology companies since 2022. Intelligence agencies from 11 countries, including the U.S., U.K., and several European nations, have attributed this activity to Russia’s GRU 85th Main Special Service Center (Military Unit 26165).

## Primary Targets

The campaign specifically targets organizations involved in:
– Coordinating and delivering foreign assistance to Ukraine
– Defense sectors within NATO member states
– Transportation and maritime operations
– Air traffic management
– IT services

Dozens of organizations across Bulgaria, Czechia, France, Germany, Greece, Italy, Moldova, the Netherlands, Poland, Romania, Slovakia, Ukraine, and the United States have been affected.

## Attack Methods

APT28 employs multiple techniques to gain initial network access:
– Password spraying and brute-force attacks
– Sophisticated spear-phishing campaigns using fake login pages
– Malware delivery through phishing
– Exploitation of vulnerabilities in Outlook (CVE-2023-23397), Roundcube (multiple CVEs), WinRAR (CVE-2023-38831), and corporate VPNs

After gaining access, the threat actors:
– Conduct reconnaissance to identify additional targets
– Use tools like Impacket, PsExec, and RDP for lateral movement
– Deploy malware families including HeadLace and MASEPIE
– Manipulate mailbox permissions to establish sustained email collection
– Exfiltrate data using PowerShell commands, EWS, and IMAP protocols

## Strategic Context

The campaign appears to be a direct response to Western aid for Ukraine. As Russian military objectives faltered and Western countries provided support to Ukraine, Unit 26165 expanded its targeting of logistics entities involved in aid delivery. The group has also targeted internet-connected cameras at Ukrainian border crossings to monitor aid shipments.

Paul Chichester, Director of Operations at the UK’s National Cyber Security Centre, warned that this campaign “presents a serious risk to targeted organizations, including those involved in the delivery of assistance to Ukraine.”

Share This Article