Russian GRU Targets Western Logistics Entities and Technology Companies
A joint cybersecurity advisory from the U.S. Department of Homeland Security's Cybersecurity and Infrastructure Security Agency highlights a Russian state-sponsored cyber campaign targeting Western logistics entities and technology companies involved in coordinating, transporting, and delivering foreign assistance to Ukraine. This campaign, conducted by the Russian General Staff Main Intelligence Directorate's 85th Main Special Service Center (85th GTsSS), military unit 26165, has been ongoing since 2022 and uses a mix of previously disclosed tactics, techniques, and procedures (TTPs). The advisory warns executives and network defenders to increase monitoring and threat hunting for known TTPs and indicators of compromise (IOCs) and to posture network defenses with a presumption of targeting.
Key Takeaways:
- The Russian GRU's 85th GTsSS, military unit 26165, has been conducting a cyber espionage-oriented campaign targeting Western logistics entities and technology companies since 2022.
- The campaign uses a mix of previously disclosed TTPs, including reconstituted password spraying capabilities, spearphishing, and modification of Microsoft Exchange mailbox permissions.
- The actors have targeted technology companies and logistics entities involved in the coordination, transport, and delivery of foreign assistance to Ukraine.
- The actors have also targeted Internet-connected cameras at Ukrainian border crossings to monitor and track aid shipments.
- The advisory warns executives and network defenders to increase monitoring and threat hunting for known TTPs and IOCs, and to posture network defenses with a presumption of targeting.
- The actors' cyber espionage-oriented campaign is likely connected to their wide-scale targeting of IP cameras in Ukraine and bordering NATO nations.
- The advisory uses the MITRE ATT&CK framework, version 17, and the MITRE D3FEND framework, version 1.0.
Statistics:
- Since 2022, Western logistics entities and IT companies have faced an "elevated risk of targeting" by the GRU's 85th GTsSS, military unit 26165. (Source: CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF)
- The actors have used a mix of previously disclosed TTPs, including reconstituted password spraying capabilities, spearphishing, and modification of Microsoft Exchange mailbox permissions. (Source: CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF)
- In late February 2022, multiple Russian state-sponsored cyber actors increased the variety of cyber operations for purposes of espionage, destruction, and influence. (Source: CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF)
- The actors have targeted Internet-connected cameras at Ukrainian border crossings to monitor and track aid shipments. (Source: CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF)
Sources:
- CSA_RUSSIAN_GRU_TARGET_LOGISTICS.PDF, "Russian GRU Targeting Western Logistics Entities and Technology Companies", U.S. Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, May 21, 2025.