A major Russian military cyber unit known in the cybersecurity world as APT28 — also referred to as “Fancy Bear” — is behind an escalating campaign of digital intrusions aimed at organisations supporting Ukraine’s war effort, according to a joint alert issued by several allied intelligence agencies including Australia.
Operating under Russia’s military intelligence agency (GRU) as Unit 26165, the group has for more than two years been systematically targeting logistics firms, defence contractors, and technology service providers across NATO countries and Ukraine itself. The objective: monitor and potentially interfere with the flow of military and humanitarian support into the country.
The hacking group has used a combination of well-known and retooled cyber techniques, including spear-phishing attacks, brute-force login attempts, and the manipulation of email server permissions—primarily via Microsoft Exchange—according to the advisory.
One particularly concerning element of the campaign involves the unauthorised access of thousands of internet-connected surveillance cameras placed along key infrastructure corridors—border crossings, railway hubs, and airports—in Ukraine and neighboring states. The attackers have used this live footage to surveil the movement of supplies destined for the Ukrainian front lines.
John Hultquist, Chief Analyst at Google’s Threat Intelligence Group, said the attacks align with Russia’s broader military goals:
“Russian military intelligence has an obvious need to track the flow of material into Ukraine, and anyone involved in that process should consider themselves targeted,” Hultquist said. “Beyond the interest in identifying support to the battlefield, there is an interest in disrupting that support through either physical or cyber means. These incidents could be precursors to other serious actions.”
The advisory points out that these activities significantly expanded after Russia’s initial invasion faltered in early 2022 and Western support for Ukraine increased. Since then, GRU operatives have widened their focus to include various transportation industries—airports, seaports, freight and rail networks—as well as IT service providers that support them.
Cybersecurity experts say APT28’s operations have also grown more deceptive. Recent phishing attempts have included adult-themed lures and impersonation of tech support personnel over phone and email to convince employees to hand over credentials or install malware.
Authorities across the UK, United States, and Europe have urged affected sectors to take immediate steps to strengthen their cyber defences. Recommended actions include updating software patches promptly, enabling multi-factor authentication on all user accounts, and monitoring networks closely for unusual activity.
APT28 is one of Russia’s most notorious cyber units, previously linked to the 2016 U.S. election interference campaign and multiple attacks on global institutions including the World Anti-Doping Agency. This latest campaign appears to be part of a broader digital offensive aimed at weakening Ukraine by disrupting the logistical lifelines that sustain its military effort.
With conflict still ongoing, intelligence officials caution that these cyber activities could lead to more serious consequences—both on and off the battlefield.







