
The United Kingdom and its allies have issued a warning about a Russian state-sponsored cyber campaign targeting organizations involved in delivering foreign aid to Ukraine.
The alert, released on Wednesday by the UK’s Government Communications Headquarters (GCHQ), highlights a significant threat posed by Russian military intelligence operations, Ukrinform reports.
“This malicious campaign by Russia’s military intelligence service presents a serious risk to targeted organizations, including those involved in the delivery of assistance to Ukraine,” said Paul Chichester, Director of Operations at the UK’s National Cyber Security Center (NCSC).
The activity is attributed to Unit 26165 of Russia’s Main Intelligence Directorate (GRU), also known as APT28. The military unit has conducted a malicious cyber campaign against both public and private organizations since 2022. This has included targeting of organizations involved in the co-ordination, transport and delivery of support to Ukraine, and across the defense, IT services, maritime, airports, ports and air traffic management systems sectors in multiple NATO members.
Unit 26165 was able to gain initial access to victim networks using a mix of previously disclosed techniques, including credential guessing, spear-phishing and exploitation of Microsoft Exchange mailbox permissions.
They also targeted internet-connected cameras at Ukrainian border crossings and near military installations to monitor and track aid shipments to Ukraine.
Executives and network defenders at technology and logistics companies should recognize the elevated threat of targeting and take immediate action to protect themselves.
Actions include increasing monitoring, using multi-factor authentication with strong factors – such as passkeys – and ensuring security updates are applied promptly to manage vulnerabilities.
The NCSC has co-sealed this advisory alongside agencies from the United States, Germany, Czech Republic, Poland, Australia, Canada, Denmark, Estonia, France and the Netherlands.
Earlier, the U.S. announced a reward of up to $10 million for information on five GRU officers involved in cyberattacks against critical infrastructure in Ukraine and several Western countries.
Source: UK, allies warn of Russian cyber activity aimed at undermining aid to Ukraine