{"id":29411,"date":"2025-05-21T19:50:11","date_gmt":"2025-05-21T19:50:11","guid":{"rendered":"https:\/\/news.godj.com\/news\/uk-exposes-russian-cyber-campaign-targeting-support-for-ukraine\/"},"modified":"2025-05-21T19:50:11","modified_gmt":"2025-05-21T19:50:11","slug":"uk-exposes-russian-cyber-campaign-targeting-support-for-ukraine","status":"publish","type":"post","link":"https:\/\/news.godj.com\/news\/uk-exposes-russian-cyber-campaign-targeting-support-for-ukraine\/","title":{"rendered":"UK exposes Russian cyber campaign targeting support for Ukraine"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div xmlns:default=\"http:\/\/www.w3.org\/2000\/svg\" id=\"\">\n<div xmlns:default=\"http:\/\/www.w3.org\/2000\/svg\" data-component=\"byline-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<div data-testid=\"byline-new\" class=\"sc-801dd632-0 eSlECZ\">\n<div data-testid=\"byline-new-contributors\" class=\"sc-801dd632-12 jSIeFi\">\n<div class=\"sc-801dd632-5 kRoBHa\">\n<div><span class=\"sc-801dd632-7 lasLGY\">Imran Rahman-Jones &amp; Chris Vallance<\/span><\/p>\n<p><span>Technology reporters<\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 gyQxwn\">\n<div data-testid=\"hero-image\" class=\"sc-4abb68ca-1 eOgpjw\"><img decoding=\"async\" sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/257b\/live\/888d3570-364e-11f0-8185-6772e52c97ad.jpg.webp\" loading=\"eager\" alt=\"Getty Images A forklift truck loads aid into a lorry\" class=\"sc-4abb68ca-0 ldLcJe\"\/><span class=\"sc-4abb68ca-2 kkAKIJ\">Getty Images<\/span><\/div>\n<\/div>\n<p><figcaption class=\"sc-1b6a1475-0 feHvAW\">Cameras monitoring supplies going into Ukraine were hacked into<\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">The UK has exposed what it says is a &#8220;malicious cyber campaign&#8221; targeting multiple organisations, including those involved in delivering foreign assistance to Ukraine<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">After a joint investigation with allies including the US, Germany and France, the UK&#8217;s National Cyber Security Centre (NCSC) said a Russian military unit had been targeting both public and private organisations since 2022.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">These include organisations involved in supplying defence, IT services and logistics support.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The security bodies of 10 Nato countries and Australia said Russian spies had used a combination of hacking techniques to gain access to networks.<\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">Some of the targets were internet-connected cameras at Ukrainian borders which monitored aid shipments going into the country.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The report also says a rough estimate of 10,000 cameras were accessed near &#8220;military installations, and rail stations, to track the movement of materials into Ukraine. <\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">It adds the &#8220;actors also used legitimate municipal services, such as traffic cams.&#8221;<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The Russian military unit blamed for the espionage is called GRU Unit 26165 but goes by a number of informal names, including <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-42056555\" class=\"sc-f9178328-0 bGFWdi\">Fancy Bear. <\/a><\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The notorious hacking team is known to have <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/world-37369705\" class=\"sc-f9178328-0 bGFWdi\">previously leaked<\/a> World Anti-Doping Agency data, and played a key role in <a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/world-us-canada-38370630\" class=\"sc-f9178328-0 bGFWdi\">the 2016 cyber-attack<\/a> on the US&#8217;s Democratic National Committee, according to security experts.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;This malicious campaign by Russia&#8217;s military intelligence service presents a serious risk to targeted organisations, including those involved in the delivery of assistance to Ukraine,&#8221; Paul Chichester, NCSC Director of Operations, said in a statement.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;We strongly encourage organisations to familiarise themselves with the threat and mitigation advice included in the advisory to help defend their networks,&#8221; he added.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Anyone involved in moving goods into Ukraine &#8220;should consider themselves targeted&#8221; by Russian military intelligence, John Hultquist, chief analyst at Google Threat Intelligence Group, said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;Beyond the interest in identifying support to the battlefield, there is an interest in disrupting that support through either physical or cyber means,&#8221; he said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;These incidents could be precursors to other serious actions.&#8221;<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 hoQmHM\">\n<div data-testid=\"image\" class=\"sc-4abb68ca-1 eOgpjw\"><img decoding=\"async\" src=\"https:\/\/static.files.bbci.co.uk\/bbcdotcom\/web\/20250508-105310-2a3fc0651-web-2.21.1-1\/grey-placeholder.png\" class=\"sc-4abb68ca-0 itgEAh hide-when-no-script\"\/><img decoding=\"async\" sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/9a33\/live\/3d5ad0c0-3654-11f0-920c-1b4eb3cd37cf.png.webp\" loading=\"lazy\" alt=\"Internet Archive A screenshot of a basic-looking website with a picture of a bear, with a large sign in front saying &quot;This domain has been seized&quot;.\" class=\"sc-4abb68ca-0 ldLcJe\"\/><span class=\"sc-4abb68ca-2 kkAKIJ\">Internet Archive<\/span><\/div>\n<\/div>\n<p><figcaption class=\"sc-1b6a1475-0 feHvAW\">The Fancy Bear website was shut down by the FBI in 2018<\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-3b6b161a-0 dEGcKf\">\n<p class=\"sc-9a00e533-0 hxuGS\">The joint cyber-security advisory said Fancy Bear had targeted organisations linked to critical infrastructure including ports, airports, air traffic management and the defence industry.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">These were in 12 mainland European countries and the US. <\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">The hackers used a combination of techniques to gain access, the report said, including guessing passwords.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Another method used is called spearphishing, where fake emails are targeted at specific people who have access to systems.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">They are presented with a fake page where they enter their login details, or encouraged to click a link which then installs malicious software. <\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">&#8220;The subjects of spearphishing emails were diverse and ranged from professional topics to adult themes,&#8221; the report said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">A vulnerability in Microsoft Outlook was also exploited to collect credentials &#8220;via specially crafted Outlook calendar appointment invitations&#8221;.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">These kinds of techniques have been &#8220;a staple tactic of this group for over a decade,&#8221; Rafe Pilling, director of threat intelligence at Sophos Counter Threat Unit, said.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Camera access &#8220;would assist in the understanding of what goods were being transported, when, in what volumes and support kinetic [weapons] targeting,&#8221; he added.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">Cyber security firm Dragos told the BBC it had been tracking hacking activity linked to that reported by the NCSC.<\/p>\n<p class=\"sc-9a00e533-0 hxuGS\">It&#8217;s chief executive Robert M. Lee said that the hackers it followed were not only interested in gaining a foothold in corporate computer networks but would infiltrate industrial control systems where they would be able to &#8220;steal important intellectual property and insights for espionage, or position themselves for disruptive attacks&#8221;.<\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-3b6b161a-0 dFZIgd\">\n<div data-testid=\"image\" class=\"sc-4abb68ca-1 eOgpjw\"><img decoding=\"async\" src=\"https:\/\/static.files.bbci.co.uk\/bbcdotcom\/web\/20250508-105310-2a3fc0651-web-2.21.1-1\/grey-placeholder.png\" class=\"sc-4abb68ca-0 itgEAh hide-when-no-script\"\/><img decoding=\"async\" sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/41d3\/live\/348b21e0-26a8-11f0-8f57-b7237f6a66e6.png.webp\" loading=\"lazy\" alt=\"A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: \u201cTech Decoded: The world\u2019s biggest tech news in your inbox every Monday.\u201d\" class=\"sc-4abb68ca-0 ldLcJe\"\/><\/div>\n<\/div>\n<\/figure>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.com\/news\/articles\/c17rrjdr79po\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Imran Rahman-Jones &amp; Chris Vallance Technology reporters Getty Images Cameras monitoring supplies going into Ukraine were hacked into The UK has exposed what it says is a &#8220;malicious cyber campaign&#8221; targeting multiple organisations, including those involved in delivering foreign assistance to Ukraine After a joint investigation with allies including the US, Germany and France, the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":29412,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[62],"tags":[4561,3158,10138,1188,1366,1649,1522],"class_list":["post-29411","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-campaign","tag-cyber","tag-exposes","tag-russian","tag-support","tag-targeting","tag-ukraine"],"_links":{"self":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/29411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/comments?post=29411"}],"version-history":[{"count":1,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/29411\/revisions"}],"predecessor-version":[{"id":29413,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/29411\/revisions\/29413"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media\/29412"}],"wp:attachment":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media?parent=29411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/categories?post=29411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/tags?post=29411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}