Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain

Russia (GRU Unit 26165 / APT28) Runs Multi-Vector (TL-2026-2031), also tracked as Europe Drone Factory Targeting Campaign, is a high-severity supply-chain compromise, first published 2026-08-16. It is attributed to GRU Unit 26165 (Russia) with high confidence, affects Microsoft Outlook, references 5 CVEs (CVE-2023-23397, CVE-2023-38831, CVE-2021-44026), maps to 19 MITRE ATT&CK techniques (T1003, T1021, T1048), and is covered by 9 detection rules and 14 indicators of compromise.

Key facts for TL-2026-2031

Threat ID
TL-2026-2031
Also known as
Europe Drone Factory Targeting Campaign, Unit 26165 Ukraine Supply Chain Campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-08-16
Last reviewed
2026-08-16
Attribution
GRU Unit 26165
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
defense, government administration, logistics, technology, manufacturing, critical infrastructure
Target regions
germany, united kingdom, spain, italy, poland, israel, netherlands, denmark, latvia, lithuania, czechia, Turkiye
Detection rules
9
Indicators of compromise
14

Malware and tooling in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

Malware and tooling: Headlace, MASEPIE, OCEANMAP, STEELHOOK, Certipy, Impacket WMIEXEC, PAExec

Truesec documents a sustained Russian intelligence campaign — GRU Unit 26165 (85th GTsSS, aka APT28/Fancy Bear/Forest Blizzard/BlueDelta) for cyber and logistics-targeting operations — combining physical surveillance, sabotage, cyber espionage and public intimidation against European defence manufacturers, logistics firms and technology suppliers backing Ukraine. Named targets include Donaustahl (CEO Stefan Thumann surveilled by two recruited agents, Dec 2025-Mar 2026) and Rheinmetall (CEO Armin Papperger, 2024 assassination plot disrupted by US/German intelligence). In April 2026 Russia's Ministry of Defence published addresses of 21 European drone-production and component sites across the UK, Germany, Netherlands, Denmark, Latvia, Lithuania, Poland, Czechia, Spain, Italy, Turkiye and Israel, which Security Council Deputy Chairman Dmitry Medvedev publicly called a list of "potential targets."

How Russia (GRU Unit 26165 / APT28) Runs Multi-Vector works

Since 2022, GRU Unit 26165 (Russia's General Staff Main Intelligence Directorate, 85th Main Special Service Center / GTsSS, publicly tracked as APT28, Fancy Bear, Forest Blizzard and BlueDelta) has run a multi-year, multi-vector campaign against the European supply chain sustaining Ukraine's defence. Truesec's August 2026 report ties together three converging lines of activity attributed to Russian state intelligence.

First, physical surveillance and intimidation of defence-industry executives: German investigators (per Die Zeit) allege that a Ukrainian national (Serhii N.) and a Romanian national (Alla S.), operating as recruited 'disposable' agents contacted via Telegram, filmed and photographed the home and headquarters of Donaustahl CEO Stefan Thumann between December 2025 and March 2026, with both arrested in a coordinated Spain/Germany operation in March 2026 and charged with acting as agents of a foreign intelligence service. This mirrors the pattern behind the July 2024 plot against Rheinmetall CEO Armin Papperger, in which US intelligence warned German authorities in time to disrupt an assassination attempt tied to Rheinmetall's build-out of an armoured-vehicle plant in Ukraine.

Second, a documented cyber-espionage program: CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A (May 2025, building on an April 2026 follow-on advisory referenced by Truesec) attributes a two-year campaign by Unit 26165 against Western logistics entities and technology companies coordinating the transport and delivery of Ukraine aid. Initial access combined credential guessing/brute forcing (routed through Tor and compromised SOHO routers/VPNs for anonymization), targeted spearphishing in the recipient's local language, and exploitation of known vulnerabilities in Microsoft Outlook (CVE-2023-23397, forced NTLM authentication leak), WinRAR (CVE-2023-38831, archive content-type spoofing) and Roundcube webmail (CVE-2021-44026, CVE-2020-35730, CVE-2020-12641). Post-compromise activity used the HEADLACE credential-phishing/LNK-dropper backdoor, the Python-based MASEPIE file-transfer/remote-access tool, and the OCEANMAP and STEELHOOK backdoors; persistence via scheduled tasks, registry Run keys/startup-folder LNK files and Exchange mailbox-permission abuse; defense evasion via Windows Event Log clearing (wevtutil); credential access via NTDS.dit extraction, GPP password recovery and Certipy ADCS abuse; lateral movement via RDP, Impacket WMIEXEC and PAExec; and exfiltration of .pst/.ost mail archives and shipment manifests over encrypted mail protocols, custom OpenSSH binaries and, in some cases, abused third-party webhook-relay services (webhook.site, pipedream.net, mockbin.org) as low-noise C2/exfil relays. A related, tactically linked sub-campaign hijacked internet-facing IP cameras at logistics sites and border crossings via crafted RTSP requests and brute-forced credentials — over 80% of targeted cameras in Ukraine, with a high concentration also in Romania and Poland — to visually track aid-shipment movements, feeding the same targeting picture used for the physical operations.

Third, sabotage and information-operations pressure: CSIS's March 2025 'Russia's Shadow War Against the West' dataset recorded Russian-linked arson/explosive incidents in Europe rising from 1 in 2023 to 26 in 2024 (at least 6 more in 2025), roughly 28% against transportation targets and 28% against government targets; incidents tied to the same actor set include a May 2024 arson at a Berlin Diehl Group munitions-linked facility and explosives intercepted at the Serbian-Hungarian border in June 2026 in a truck bound for Bavaria, where investigators have not ruled out a second executive-targeting plot. In April 2026, Russia's Ministry of Defence published two target lists — 'Branches of Ukrainian Companies in Europe' (11 sites) and 'Foreign Enterprises Producing Components' (10 sites) — naming drone and component manufacturers across 12 countries, after which Medvedev stated on X that the list 'must be taken literally... a list of potential targets for the Russian armed forces,' explicitly fusing the surveillance/cyber-espionage targeting picture with a public threat of kinetic strikes.

Taken together, the campaign represents a hybrid warfare posture: cyber-espionage and IP-camera surveillance build the targeting picture, recruited 'disposable' human agents conduct physical surveillance and pre-attack reconnaissance, and sabotage/assassination planning plus public information operations (Medvedev's threats) convert that intelligence into intimidation and, potentially, kinetic action against a supply chain no single company or nation can defend against in isolation.

MITRE ATT&CK techniques used in TL-2026-2031

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force; T1187 Forced Authentication

Lateral Movement

T1021 Remote Services

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Persistence

T1053 Scheduled Task/Job; T1098 Account Manipulation; T1547 Boot or Logon Autostart Execution

Discovery

T1087 Account Discovery

Command and Control

T1090 Proxy; T1573 Encrypted Channel

Collection

T1114 Email Collection; T1125 Video Capture; T1560 Archive Collected Data

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing

Execution

T1204 User Execution

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

  • Microsoft — Outlook
    Vulnerable versions: Outlook 2013; Outlook 2016; Microsoft 365 Apps for Enterprise; Office 2019; Office LTSC 2021
    Fixed in: March 2023 security update and later
  • RARLAB — WinRAR
    Vulnerable versions: before 6.23
    Fixed in: 6.23 and later
  • Roundcube — Roundcube Webmail
    Vulnerable versions: versions affected by CVE-2021-44026; versions affected by CVE-2020-35730; versions affected by CVE-2020-12641
    Fixed in: current patched releases
  • Various — Internet-connected IP cameras (logistics sites, border crossings)
    Vulnerable versions: devices with default/weak credentials and exposed RTSP
    Fixed in: credential hardening and network segmentation, not a vendor patch
  • Donaustahl — Corporate leadership / physical security
    Vulnerable versions: pre-2026 unprotected executive residence/routine
    Fixed in: N/A - enhanced protective security since March 2026
  • Rheinmetall — Corporate leadership / physical security
    Vulnerable versions: pre-2024 unprotected executive routine
    Fixed in: N/A - enhanced CEO protection since July 2024

Remediation for Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

Patches

  • Microsoft Outlook: apply the March 2023 security update remediating CVE-2023-23397.
  • WinRAR: upgrade to 6.23 or later, remediating CVE-2023-38831.
  • Roundcube Webmail: upgrade past the versions vulnerable to CVE-2021-44026, CVE-2020-35730 and CVE-2020-12641.

Immediate actions

  • Executives and family members at named/likely-targeted defence-supply-chain firms should engage close-protection and residential counter-surveillance support and review OSINT/social-media exposure.
  • Patch Microsoft Outlook against CVE-2023-23397, WinRAR against CVE-2023-38831, and Roundcube Webmail against CVE-2021-44026/CVE-2020-35730/CVE-2020-12641 — all four products are actively targeted by this actor.
  • Change default credentials and restrict internet exposure of RTSP/IP-camera management interfaces at logistics sites and border-adjacent facilities; segment camera VLANs from operational networks.
  • Enforce MFA with phishing-resistant factors (FIDO2/hardware tokens, not SMS/push) on VPN, webmail and Exchange/M365 admin accounts, with lockout after failed logins to blunt distributed brute-force/password-spray activity.
  • Block or tightly monitor outbound traffic to public webhook-relay services (webhook.site, pipedream.net, mockbin.org, similar) from logistics/shipment-management systems; alert on first-seen usage.

Workarounds

  • Where patching Outlook is delayed, block outbound SMB (TCP 445) at the perimeter and add affected users to the Protected Users security group to mitigate NTLM relay from CVE-2023-23397.
  • Disable or firewall-restrict RTSP (TCP/UDP 554) on internet-facing IP cameras where firmware/credential hardening cannot be completed immediately.

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to HEADLACE/MASEPIE/OCEANMAP/STEELHOOK TTPs (LNK-based execution, wevtutil log clearing, NTDS.dit access, scheduled-task persistence).
  • Audit and restrict commercial VPN / anonymization-service egress (per US/UK guidance: block or alert on CactusVPN, IPVanish, NordVPN, ProtonVPN, Surfshark, WorldVPN and Tor exit traffic) from logistics and defence-industry networks.
  • Establish a coordinated threat-sharing channel between defence-industry security teams, national CERTs (BSI, CERT-UA, NCSC-UK) and law enforcement for physical-surveillance and cyber indicators, since this actor deliberately fuses both.
  • Build an insider/agent-recruitment awareness program for staff at logistics and IT-services firms, given the actor's use of low-level agents recruited via Telegram for physical tasking.

CVEs associated with Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

CVE-2023-23397, CVE-2023-38831, CVE-2021-44026, CVE-2020-35730, CVE-2020-12641

Weaknesses (CWE) in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

CWE-294, CWE-20, CWE-345, CWE-351

Timeline of Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

  • GRU Unit 26165 begins expanding cyber-espionage targeting of Western logistics entities and technology companies involved in coordinating Ukraine aid delivery, per CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A.
  • Arson at a Berlin factory owned by the Diehl Group, suspected by Western officials to be Russian sabotage aimed at disrupting arms-delivery supply chains to Ukraine.
  • US intelligence warns German authorities of a Russian plot to assassinate Rheinmetall CEO Armin Papperger; German security services disrupt the plot and increase his protection.
  • CSIS publishes 'Russia's Shadow War Against the West,' documenting a near-tripling of Russian-linked sabotage/subversion incidents in Europe between 2023 and 2024 (1 to 26 arson/explosive incidents), with transportation and government sectors most targeted.
  • CISA, NSA, FBI and international partners issue joint cybersecurity advisory AA25-141A detailing GRU Unit 26165's two-year cyber-espionage campaign against Western logistics and technology firms, including IP-camera hijacking at Ukrainian border crossings.
  • Two agents recruited by Russian intelligence begin physical surveillance of Donaustahl CEO Stefan Thumann's home and company headquarters (period runs through March 2026), per Die Zeit.
  • German and Spanish law enforcement arrest the two agents (a Ukrainian national and a Romanian national) surveilling the Donaustahl CEO in a coordinated operation; Germany's Federal Prosecutor charges both as agents of a foreign intelligence service.
  • Russia's Ministry of Defence publishes two lists naming 21 European drone-production and component-manufacturing sites across 12 countries, including 'Branches of Ukrainian Companies in Europe' and 'Foreign Enterprises Producing Components.'
  • Russian Security Council Deputy Chairman Dmitry Medvedev states on X that the Ministry of Defence's published site list 'must be taken literally' as 'a list of potential targets for the Russian armed forces,' explicitly threatening kinetic strikes.
  • Explosives are discovered at the Serbian-Hungarian border in a truck heading to Bavaria, Germany; investigators do not rule out preparation for another attack on a German defense-industry executive. Two suspects arrested with confirmed contacts to Russian intelligence representatives.
  • Truesec publishes a consolidated report tying the physical surveillance, sabotage, cyber-espionage and public-intimidation threads together as a single coordinated Russian campaign against Europe's Ukraine defence supply chain.

Sources cited for Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

Threats related to Russia (GRU Unit 26165 / APT28) Runs Multi-Vector

Detection coverage for TL-2026-2031

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2031 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats