A sophisticated cyberespionage campaign by Russian state-sponsored hackers known as APT28 (Fancy Bear/Forest Blizzard) has been targeting international organizations since 2022 to monitor and potentially disrupt aid efforts to Ukraine, according to a joint advisory from 21 intelligence and cybersecurity agencies across multiple countries.
## Wide-Ranging Targets
The hackers have compromised entities in multiple sectors including defense, transportation, IT services, air traffic, and maritime across 13 countries:
– United States
– Bulgaria
– Czechia
– France
– Germany
– Greece
– Italy
– Moldova
– Netherlands
– Poland
– Romania
– Slovakia
– Ukraine
## Sophisticated Attack Methods
APT28, identified as the Russian GRU 85th GTsSS (military unit 26165), has employed various tactics to gain initial access:
– Password spraying and credential guessing
– Spear-phishing campaigns to steal credentials or deliver malware
– Exploiting vulnerabilities including:
– Outlook NTLM vulnerability (CVE-2023-23397)
– Roundcube webmail vulnerabilities (CVE-2020-12641, CVE-2020-35730, CVE-2021-44026)
– WinRAR vulnerability (CVE-2023-38831)
– Targeting corporate VPNs and internet-facing infrastructure
## Stealth Techniques
To maintain stealth, the hackers:
– Routed communications through compromised small office/home office devices near targets
– Used native commands and open-source tools for lateral movement
– Enrolled compromised accounts in MFA to increase trust levels
– Deployed backdoors including Headlace and Masepie
– Timed exfiltration sessions carefully to avoid detection
## Camera Surveillance Operations
A significant aspect of the campaign involves hacking camera feeds to monitor aid shipments to Ukraine:
– Over 10,000 cameras targeted
– More than 80% located in Ukraine
– Nearly 1,000 in Romania
– Cameras at border crossings, military installations, rail stations, and other strategic locations
## Expert Warning
John Hultquist, Google Threat Intelligence Group chief analyst, warned that these activities could be “precursors to other serious actions” and advised that anyone involved in sending material aid to Ukraine “should consider themselves targeted.”
The joint advisory includes security mitigations, detection guidance, and indicators of compromise to help organizations protect themselves against this ongoing threat.
