A long-running cyberespionageattributed to the Russian state-sponsored group APT28 – also known as Fancy Bear or Forest Blizzard – has targeted international organizations and critical infrastructure since 2022, with the primary goal of undermining efforts to support Ukraine.
According to reports, the attacks focused on strategic sectors such as defense, transportation, IT services, air traffic management and shipping, with targets in 12 European countries as well as the United States.

Of particular concern is the fact that hackers monitored the movement of military and humanitarian material to Ukraine, illegally gaining access to private security cameras installed in sensitive locations, such as border crossings, military bases and train stations.
See also: Russian hackers develop SilentPrism and DarkWisp backdoors
This escalating threat has mobilized the international community: 21 state intelligence and cybersecurity agencies from nearly a dozen countries have issued a joint warning detailing the tactics, techniques, and procedures (TTPs) used by APT28. The hacking group is linked to the 85th Special Services Center (GTsSS) of the Russian General Intelligence Staff (GRU), also known as military unit 26165.
APT28 combines different techniques to avoid detection
Russian cyber espionage group APT28 appears to have escalated its activity since 2022, using a wide range of techniques to organizations strategic. According to a new security report, the Russian APT is leveraging tactics such as password spraying, targeted spear-phishing, and known exploits in Microsoft Exchangeto infiltrate corporate environments.
After gaining initial access to the primary target, the attackers target other businesses — primarily in the transportation — that are connected to the initial victim. Hackers exploit relationships of trust and connections for further penetration.
At the same time, the group has also targeted surveillance infrastructure on the Ukrainian border, gaining access to internet-connected cameras, with the aim of monitoring flows of humanitarian and military aid.
APT28 operations have been detected in numerous countries: the USA, Germany, France, Italy, the Netherlands, Poland, the Czech Republic, Slovakia, Romania, Bulgaria, Greece, Moldova and of course Ukraine.
According to the findings, the techniques used for initial breach include:
- Credential guessing or brute force
- Targeted spear-phishing either to steal credentials or install malware
- Exploiting Microsoft Outlook vulnerability (CVE-2023-23397)
- Exploitation of known zero-day vulnerabilities in Roundcube Webmail (CVE-2020-12641, CVE-2020-35730, CVE-2021-44026)
- SQL injection and exploits in corporate VPNs
- Exploiting WinRAR vulnerability (CVE-2023-38831)
To conceal their activity, cybercriminals launched their malicious activity through compromised SOHO (Small Office/Home Office) devices that were geographically close to the targets.
See also: Russian hackers Gamaredon target Ukraine with Remcos RAT
Once they establish a presence on the network, hackers conduct reconnaissance, focusing on contacts related to cybersecurity, transportation management, and third-party cooperating companies, with the aim of further spreading the attack.
According to the report, the Russian APT group utilized advanced lateral movement and data extraction, leveraging native tools and open source software to stay under the radar of detection systems. Among the tools used were PsExec, Impacket, Remote Desktop Protocol (RDP), Certipy , and ADExplorer, which allowed access to critical Active Directory information.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The attackers also identified Office 365 user lists, and then targeted email accounts. In a subsequent stage, APT28 hackers focused on accounts related to aid shipments to Ukraine, gaining access to information such as recipients and senders of shipments, shipment content, itineraries, container numbers, and final destinations.
Researchers documented the use of malware such as Headlace and Masepie, which were used to allow attackers to remain on networks and gradually extract data.
The extraction method varies depending on the environment of each target: living-off-the-land (LOtL) binaries and malware. In several cases, the attacks remained invisible thanks to the use of local, trusted infrastructure, the use of legitimate protocols , etc.

Tampering with connected cameras for transportation monitoring
One of the most important aspects of the cyber espionage campaign, as we mentioned earlier, is targeted surveillance through compromised cameras — whether it’s private networks, traffic cameras, military installations, or key points like train stations and border crossings. The goal of these moves was to monitor the movement of military and humanitarian supplies to Ukraine.
Over 10,000 cameras targeted by APT28
More than 10,000 surveillance cameras have been targeted by the Russian cyber-espionage group APT28, according to a joint report by government cybersecurity agencies. 80% of these devices are located within Ukraine, while a significant number – almost 1,000 cameras – have been detected in Romania.
This strategy is reportedly aimed at monitoring the movement of humanitarian and military aid to Ukraine, reinforcing suspicions that APT28's campaign operates in addition to physical warfare operations.
See also: What new techniques are Russian hackers APT29 using?
John Hultquist, a principal analyst at Google's Threat Intelligence Group, told BleepingComputer that the breaches are not limited to intelligence gathering, but indicate possible future offensive actions. "These actions could be a prelude to more serious attacks," Hultquist stressed, adding that anyone involved in managing or transporting aid to Ukraine should consider themselves a potential target.
The joint report cybersecurity, published by agencies from nearly a dozen countries, includes both general mitigation and detection measures and technical indicators of compromise (IoCs). These include IP addresses, malicious file names, known exploits such as the Outlook vulnerability CVE-2023-23397, as well as information about software and email providers used by the threat actor.
The attacks attributed to the Russian group APT28 (also known as Fancy Bear or Forest Blizzard) reveal a combination of high technical skill and strategic planning, which goes beyond the boundaries of traditional cyberespionage.
These attacks are not simple security breaches. They are signs of a new form of warfare, where technology is directly used to influence, delay, or even destroy critical support mechanisms. These are state-sponsored operations with geopolitical significance, which show that cyberwarfare has already begun and is affecting physical reality.
Source: www.bleepingcomputer.com
