top of page

Embedded Access: GRU Unit 26165 Targeting Western Logistics and Tech Infrastructure

  • Sep 29, 2025
  • 2 min read

On May 21, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with allied partners, issued Advisory AA25-141A. It confirms an ongoing cyberespionage campaign by Russia’s GRU Unit 26165 (APT28, also known as Fancy Bear), targeting logistics and technology networks directly tied to Western support for Ukraine.

This is not speculative. These actors are inside operational networks right now.

Targets and Operational Focus

Since early 2022, Russian military cyber units have been collecting intelligence on:

  • Defense and weapons logistics

  • Commercial shipping and air cargo

  • Port, rail, and airport infrastructure

  • Maritime tracking systems and ATC

  • IT services supporting NATO-aligned missions

Compromised entities span the U.S., Germany, Poland, Romania, Czech Republic, Moldova, France, Italy, and more (CISA Advisory; Critical Path Security).

Tactics and Toolsets

GRU’s cyber operators are using reliable, well-obfuscated tools to access and persist inside these networks.

Initial Access Techniques

  • Brute force and credential stuffing through anonymized nodes (Tor, commercial VPNs)

  • Spearphishing with spoofed Microsoft 365 login portals

  • Exploits: CVE-2023-23397 (Outlook NTLM leak), CVE-2023-38831 (WinRAR archive vulnerability)

Post-Compromise Activity

  • Impacket and PsExec for lateral movement

  • Scheduled tasks created via schtasks

  • OpenSSH and remote desktop protocols tunneled over non-standard ports

Exfiltration Tactics

  • Shared mailbox access for persistent surveillance

  • Log deletion using wevtutil

  • Data exfil via encrypted SSH tunnels (CISA)

Strategic Implications

This campaign is about visibility, not disruption—yet. GRU is watching the flow of Western materiel, aid, and information. By targeting logistics and IT backbone infrastructure, they gain pre-crisis access and leverage.

This is classic pre-positioning. Map the routes now. Decide when to strike later.

The most affected sectors are:

  • Third-party logistics (3PLs)

  • Defense contractors and subcontractors

  • Telecom and hosting providers

  • Cloud-based IT service firms

If your network touches movement, weapons, or bandwidth to Ukraine—you are a live target.

NOVINT Recommendations

  1. Audit and hunt for known TTPs and IOCs Use the full IOC list provided in AA25-141A and from NSA/FBI advisories.

  2. Segment communications systems from operational networks Treat systems used for partner coordination as high-side.

  3. Lock down external IT providers Several breaches exploited third-party access paths (Critical Path).

  4. Use strict access controls and 2FA on all remote systems Credential reuse and poor MFA are still the weakest links.

  5. Establish direct communication with CISA and FBI These campaigns are not isolated. Intelligence sharing is part of the mitigation strategy (CISA ShieldUp).

At November Intelligence, we don’t treat these campaigns as IT problems. We treat them as what they are—intelligence operations.

If your organization is moving critical goods or providing enabling services, your threat surface includes state actors. We help you map it, contain it, and prepare for escalation.

You are not just supporting logistics. You are part of the operating picture.

4 Comments


billy24barne.s7.8.3.5
2 days ago

du doan xsmb đang nói tới mốc ngày 3 9 2026 nên mình ghé xem thử cách họ trình bày thôi, không phải kiểu vào là bị ngợp chữ ngay; tiêu đề “Soi cầu MB ngày 3 9 2026” để lớn, nhìn phát biết đúng bài theo ngày, khỏi phải lục nhiều, kéo xuống là thấy phần dự đoán XSMB hôm nay được chia thành mấy khối ngắn, mỗi khối tách ý rõ nên đọc lướt cũng nắm được; mình hay xem trên điện thoại nên đánh giá cao chỗ họ không nhồi quá nhiều đoạn dài liền tù tì, cảm giác đỡ mỏi mắt; nói chung nếu chỉ cần xem nhanh cho đúng ngày thì ổn, vì mấy heading…

Like

lydiaharve.y50.4.4.4
Aug 27

kèo nhà cái mình thấy bạn bè nhắc suốt nên cũng bấm vào nghía thử cho biết. Mình không đọc kỹ nội dung đâu, chỉ lướt qua xem trang họ làm có dễ nhìn không. Ấn tượng ban đầu là giao diện khá sáng sủa, khoảng cách giữa các phần vừa đủ nên kéo xuống không bị rối. Mấy khối thông tin được chia tách rõ ràng, nhìn cái là biết đang ở đoạn nào chứ không bị dính chùm vào nhau. Mình cũng để ý thanh menu đặt ngay chỗ dễ thấy nên đổi qua lại mấy mục khá nhanh, không phải mò mẫm. Nói chung kiểu trình bày gọn gàng, nhất là cách họ để menu điều hướng…

Like

davidthom.a.s.282.55
Aug 21

Bài viết dễ thương và gợi nhiều ký ức, cảm ơn bạn đã chia sẻ, mình cũng lưu lại để đọc lại sau. Dạo này mình hay để ý cách các nền tảng giải trí sắp xếp giao diện nên vào xem chủ yếu để nhìn bố cục, cách chia mục và hiển thị bảng thông tin, chứ không soi từng trò. Mình gom mấy thứ mình hay xem vào một trang cho tiện, ai cần thì ghé https://www.myminifactory.com/users/tranlan

Like

nolafo.wle156+abc123
Aug 12

Mình xem xổ số kiểu cho vui là chính, coi như thêm chút giải trí chứ không đặt nặng chuyện trúng hay không. Trước đây nghe người ta bàn về mấy “cầu” này nọ, mình cũng nửa tin nửa ngờ, nhưng theo dõi một thời gian thì đôi lúc thấy có vài dạng lặp lại nên cũng tò mò. Mỗi khi đọc nhận định của ai đó, mình thường ghi lại vài ý ngắn gọn rồi sau đó so kết quả, để khỏi bị cảm giác kiểu “biết trước rồi”. Có hôm trúng được chút thì vui thật, nhưng cũng nhiều lần sai bét nên mình tự nhắc là đừng tin tuyệt đối. Thỉnh thoảng mình lướt cho có chuyện…

Like
bottom of page