News Security Technology

Russia Targeting Ukraine Aid Operations In Cyber Campaign

cyber attacks india
UK and allies say GRU-linked hackers used cameras, spearphishing and Outlook flaws to breach systems

The UK has accused Russia’s military intelligence agency of orchestrating a wide-ranging cyber-espionage campaign against public and private organisations aiding Ukraine, including those involved in defence, logistics and IT support.

The National Cyber Security Centre (NCSC), part of GCHQ, said the campaign, attributed to GRU Unit 26165 – also known by aliases such as Fancy Bear – has been ongoing since 2022. The findings, revealed in a joint investigation with intelligence partners in the US, Germany, France and other NATO countries, point to a concerted effort by Moscow to infiltrate networks connected to the war effort in Ukraine.

The NCSC said the Russian group had compromised internet-connected surveillance cameras positioned along Ukraine’s borders, many of which monitored the movement of foreign aid. Around 10,000 cameras are believed to have been accessed, including those near military sites and railway stations used for transporting supplies.

The advisory notes that legitimate municipal services – such as traffic monitoring systems – were also exploited, allowing Russian operatives to track logistics and potentially support physical attacks.

“This malicious campaign by Russia’s military intelligence service presents a serious risk to targeted organisations, including those involved in the delivery of assistance to Ukraine,” said Paul Chichester, the NCSC’s director of operations. “We strongly encourage organisations to familiarise themselves with the threat and mitigation advice included in the advisory to help defend their networks.”

According to the joint report, Fancy Bear’s targets included entities linked to critical infrastructure in 12 mainland European countries and the US. These included ports, airports, air traffic control systems and defence companies.

John Hultquist, chief analyst at Google’s Threat Intelligence Group, warned that the campaign could signal more dangerous activity ahead. “Anyone involved in moving goods into Ukraine should consider themselves targeted,” he said. “Beyond the interest in identifying support to the battlefield, there is an interest in disrupting that support through either physical or cyber means. These incidents could be precursors to other serious actions.”

The group is accused of deploying a range of techniques to access systems. These included brute-force password guessing, exploiting vulnerabilities in Microsoft Outlook, and spearphishing – a method involving deceptive emails crafted to trick specific individuals into handing over credentials or downloading malware.

In one tactic, attackers used doctored calendar invitations in Outlook to harvest login details. Another method involved emails on a wide range of topics – from work-related subjects to adult content – designed to lure recipients into clicking malicious links.

“These kinds of techniques have been a staple tactic of this group for over a decade,” said Rafe Pilling, director of threat intelligence at Sophos’ Counter Threat Unit. Gaining access to border cameras, he added, would help “understand what goods were being transported, when, in what volumes – and support kinetic targeting.”

Cybersecurity firm Dragos, which has tracked similar activity, warned the hackers were not only interested in espionage, but also in infiltrating industrial control systems. Robert M Lee, the company’s chief executive, said the intrusions were part of a broader campaign that could enable “disruptive attacks” or the theft of critical intellectual property.

Fancy Bear has previously been linked to high-profile operations including the 2016 hack of the US Democratic National Committee and the leak of data from the World Anti-Doping Agency.

The latest revelations underscore growing concerns about the cyber dimension of the Ukraine conflict and the potential for wider escalation.

Leave a Reply

Your email address will not be published. Required fields are marked *