Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain
Russia (GRU Unit 26165 / APT28) Runs Multi-Vector (TL-2026-2031), also tracked as Europe Drone Factory Targeting Campaign, is a high-severity supply-chain compromise, first published 2026-08-16. It is attributed to GRU Unit 26165 (Russia) with high confidence, affects Microsoft Outlook, references 5 CVEs (CVE-2023-23397, CVE-2023-38831, CVE-2021-44026), maps to 19 MITRE ATT&CK techniques (T1003, T1021, T1048), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2031
- Threat ID
- TL-2026-2031
- Also known as
- Europe Drone Factory Targeting Campaign, Unit 26165 Ukraine Supply Chain Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-08-16
- Last reviewed
- 2026-08-16
- Attribution
- GRU Unit 26165
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- defense, government administration, logistics, technology, manufacturing, critical infrastructure
- Target regions
- germany, united kingdom, spain, italy, poland, israel, netherlands, denmark, latvia, lithuania, czechia, Turkiye
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
Malware and tooling: Headlace, MASEPIE, OCEANMAP, STEELHOOK, Certipy, Impacket WMIEXEC, PAExec
Truesec documents a sustained Russian intelligence campaign — GRU Unit 26165 (85th GTsSS, aka APT28/Fancy Bear/Forest Blizzard/BlueDelta) for cyber and logistics-targeting operations — combining physical surveillance, sabotage, cyber espionage and public intimidation against European defence manufacturers, logistics firms and technology suppliers backing Ukraine. Named targets include Donaustahl (CEO Stefan Thumann surveilled by two recruited agents, Dec 2025-Mar 2026) and Rheinmetall (CEO Armin Papperger, 2024 assassination plot disrupted by US/German intelligence). In April 2026 Russia's Ministry of Defence published addresses of 21 European drone-production and component sites across the UK, Germany, Netherlands, Denmark, Latvia, Lithuania, Poland, Czechia, Spain, Italy, Turkiye and Israel, which Security Council Deputy Chairman Dmitry Medvedev publicly called a list of "potential targets."
How Russia (GRU Unit 26165 / APT28) Runs Multi-Vector works
Since 2022, GRU Unit 26165 (Russia's General Staff Main Intelligence Directorate, 85th Main Special Service Center / GTsSS, publicly tracked as APT28, Fancy Bear, Forest Blizzard and BlueDelta) has run a multi-year, multi-vector campaign against the European supply chain sustaining Ukraine's defence. Truesec's August 2026 report ties together three converging lines of activity attributed to Russian state intelligence.
First, physical surveillance and intimidation of defence-industry executives: German investigators (per Die Zeit) allege that a Ukrainian national (Serhii N.) and a Romanian national (Alla S.), operating as recruited 'disposable' agents contacted via Telegram, filmed and photographed the home and headquarters of Donaustahl CEO Stefan Thumann between December 2025 and March 2026, with both arrested in a coordinated Spain/Germany operation in March 2026 and charged with acting as agents of a foreign intelligence service. This mirrors the pattern behind the July 2024 plot against Rheinmetall CEO Armin Papperger, in which US intelligence warned German authorities in time to disrupt an assassination attempt tied to Rheinmetall's build-out of an armoured-vehicle plant in Ukraine.
Second, a documented cyber-espionage program: CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A (May 2025, building on an April 2026 follow-on advisory referenced by Truesec) attributes a two-year campaign by Unit 26165 against Western logistics entities and technology companies coordinating the transport and delivery of Ukraine aid. Initial access combined credential guessing/brute forcing (routed through Tor and compromised SOHO routers/VPNs for anonymization), targeted spearphishing in the recipient's local language, and exploitation of known vulnerabilities in Microsoft Outlook (CVE-2023-23397, forced NTLM authentication leak), WinRAR (CVE-2023-38831, archive content-type spoofing) and Roundcube webmail (CVE-2021-44026, CVE-2020-35730, CVE-2020-12641). Post-compromise activity used the HEADLACE credential-phishing/LNK-dropper backdoor, the Python-based MASEPIE file-transfer/remote-access tool, and the OCEANMAP and STEELHOOK backdoors; persistence via scheduled tasks, registry Run keys/startup-folder LNK files and Exchange mailbox-permission abuse; defense evasion via Windows Event Log clearing (wevtutil); credential access via NTDS.dit extraction, GPP password recovery and Certipy ADCS abuse; lateral movement via RDP, Impacket WMIEXEC and PAExec; and exfiltration of .pst/.ost mail archives and shipment manifests over encrypted mail protocols, custom OpenSSH binaries and, in some cases, abused third-party webhook-relay services (webhook.site, pipedream.net, mockbin.org) as low-noise C2/exfil relays. A related, tactically linked sub-campaign hijacked internet-facing IP cameras at logistics sites and border crossings via crafted RTSP requests and brute-forced credentials — over 80% of targeted cameras in Ukraine, with a high concentration also in Romania and Poland — to visually track aid-shipment movements, feeding the same targeting picture used for the physical operations.
Third, sabotage and information-operations pressure: CSIS's March 2025 'Russia's Shadow War Against the West' dataset recorded Russian-linked arson/explosive incidents in Europe rising from 1 in 2023 to 26 in 2024 (at least 6 more in 2025), roughly 28% against transportation targets and 28% against government targets; incidents tied to the same actor set include a May 2024 arson at a Berlin Diehl Group munitions-linked facility and explosives intercepted at the Serbian-Hungarian border in June 2026 in a truck bound for Bavaria, where investigators have not ruled out a second executive-targeting plot. In April 2026, Russia's Ministry of Defence published two target lists — 'Branches of Ukrainian Companies in Europe' (11 sites) and 'Foreign Enterprises Producing Components' (10 sites) — naming drone and component manufacturers across 12 countries, after which Medvedev stated on X that the list 'must be taken literally... a list of potential targets for the Russian armed forces,' explicitly fusing the surveillance/cyber-espionage targeting picture with a public threat of kinetic strikes.
Taken together, the campaign represents a hybrid warfare posture: cyber-espionage and IP-camera surveillance build the targeting picture, recruited 'disposable' human agents conduct physical surveillance and pre-attack reconnaissance, and sabotage/assassination planning plus public information operations (Medvedev's threats) convert that intelligence into intimidation and, potentially, kinetic action against a supply chain no single company or nation can defend against in isolation.
MITRE ATT&CK techniques used in TL-2026-2031
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force; T1187 Forced Authentication
Lateral Movement
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Persistence
T1053 Scheduled Task/Job; T1098 Account Manipulation; T1547 Boot or Logon Autostart Execution
Discovery
Command and Control
T1090 Proxy; T1573 Encrypted Channel
Collection
T1114 Email Collection; T1125 Video Capture; T1560 Archive Collected Data
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Execution
Reconnaissance
Affected products and versions in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
- Microsoft — Outlook
Vulnerable versions: Outlook 2013; Outlook 2016; Microsoft 365 Apps for Enterprise; Office 2019; Office LTSC 2021
Fixed in: March 2023 security update and later - RARLAB — WinRAR
Vulnerable versions: before 6.23
Fixed in: 6.23 and later - Roundcube — Roundcube Webmail
Vulnerable versions: versions affected by CVE-2021-44026; versions affected by CVE-2020-35730; versions affected by CVE-2020-12641
Fixed in: current patched releases - Various — Internet-connected IP cameras (logistics sites, border crossings)
Vulnerable versions: devices with default/weak credentials and exposed RTSP
Fixed in: credential hardening and network segmentation, not a vendor patch - Donaustahl — Corporate leadership / physical security
Vulnerable versions: pre-2026 unprotected executive residence/routine
Fixed in: N/A - enhanced protective security since March 2026 - Rheinmetall — Corporate leadership / physical security
Vulnerable versions: pre-2024 unprotected executive routine
Fixed in: N/A - enhanced CEO protection since July 2024
Remediation for Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
Patches
- Microsoft Outlook: apply the March 2023 security update remediating CVE-2023-23397.
- WinRAR: upgrade to 6.23 or later, remediating CVE-2023-38831.
- Roundcube Webmail: upgrade past the versions vulnerable to CVE-2021-44026, CVE-2020-35730 and CVE-2020-12641.
Immediate actions
- Executives and family members at named/likely-targeted defence-supply-chain firms should engage close-protection and residential counter-surveillance support and review OSINT/social-media exposure.
- Patch Microsoft Outlook against CVE-2023-23397, WinRAR against CVE-2023-38831, and Roundcube Webmail against CVE-2021-44026/CVE-2020-35730/CVE-2020-12641 — all four products are actively targeted by this actor.
- Change default credentials and restrict internet exposure of RTSP/IP-camera management interfaces at logistics sites and border-adjacent facilities; segment camera VLANs from operational networks.
- Enforce MFA with phishing-resistant factors (FIDO2/hardware tokens, not SMS/push) on VPN, webmail and Exchange/M365 admin accounts, with lockout after failed logins to blunt distributed brute-force/password-spray activity.
- Block or tightly monitor outbound traffic to public webhook-relay services (webhook.site, pipedream.net, mockbin.org, similar) from logistics/shipment-management systems; alert on first-seen usage.
Workarounds
- Where patching Outlook is delayed, block outbound SMB (TCP 445) at the perimeter and add affected users to the Protected Users security group to mitigate NTLM relay from CVE-2023-23397.
- Disable or firewall-restrict RTSP (TCP/UDP 554) on internet-facing IP cameras where firmware/credential hardening cannot be completed immediately.
Longer-term hardening
- Deploy EDR with behavioral detection tuned to HEADLACE/MASEPIE/OCEANMAP/STEELHOOK TTPs (LNK-based execution, wevtutil log clearing, NTDS.dit access, scheduled-task persistence).
- Audit and restrict commercial VPN / anonymization-service egress (per US/UK guidance: block or alert on CactusVPN, IPVanish, NordVPN, ProtonVPN, Surfshark, WorldVPN and Tor exit traffic) from logistics and defence-industry networks.
- Establish a coordinated threat-sharing channel between defence-industry security teams, national CERTs (BSI, CERT-UA, NCSC-UK) and law enforcement for physical-surveillance and cyber indicators, since this actor deliberately fuses both.
- Build an insider/agent-recruitment awareness program for staff at logistics and IT-services firms, given the actor's use of low-level agents recruited via Telegram for physical tasking.
CVEs associated with Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
CVE-2023-23397, CVE-2023-38831, CVE-2021-44026, CVE-2020-35730, CVE-2020-12641
Weaknesses (CWE) in Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
CWE-294, CWE-20, CWE-345, CWE-351
Timeline of Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
- GRU Unit 26165 begins expanding cyber-espionage targeting of Western logistics entities and technology companies involved in coordinating Ukraine aid delivery, per CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A.
- Arson at a Berlin factory owned by the Diehl Group, suspected by Western officials to be Russian sabotage aimed at disrupting arms-delivery supply chains to Ukraine.
- US intelligence warns German authorities of a Russian plot to assassinate Rheinmetall CEO Armin Papperger; German security services disrupt the plot and increase his protection.
- CSIS publishes 'Russia's Shadow War Against the West,' documenting a near-tripling of Russian-linked sabotage/subversion incidents in Europe between 2023 and 2024 (1 to 26 arson/explosive incidents), with transportation and government sectors most targeted.
- CISA, NSA, FBI and international partners issue joint cybersecurity advisory AA25-141A detailing GRU Unit 26165's two-year cyber-espionage campaign against Western logistics and technology firms, including IP-camera hijacking at Ukrainian border crossings.
- Two agents recruited by Russian intelligence begin physical surveillance of Donaustahl CEO Stefan Thumann's home and company headquarters (period runs through March 2026), per Die Zeit.
- German and Spanish law enforcement arrest the two agents (a Ukrainian national and a Romanian national) surveilling the Donaustahl CEO in a coordinated operation; Germany's Federal Prosecutor charges both as agents of a foreign intelligence service.
- Russia's Ministry of Defence publishes two lists naming 21 European drone-production and component-manufacturing sites across 12 countries, including 'Branches of Ukrainian Companies in Europe' and 'Foreign Enterprises Producing Components.'
- Russian Security Council Deputy Chairman Dmitry Medvedev states on X that the Ministry of Defence's published site list 'must be taken literally' as 'a list of potential targets for the Russian armed forces,' explicitly threatening kinetic strikes.
- Explosives are discovered at the Serbian-Hungarian border in a truck heading to Bavaria, Germany; investigators do not rule out preparation for another attack on a German defense-industry executive. Two suspects arrested with confirmed contacts to Russian intelligence representatives.
- Truesec publishes a consolidated report tying the physical surveillance, sabotage, cyber-espionage and public-intimidation threads together as a single coordinated Russian campaign against Europe's Ukraine defence supply chain.
Sources cited for Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
- Russia Targets Businesses and Officials Behind Europe's Ukraine Defence Supply Chain
- Russian GRU Targeting Western Logistics Entities and Technology Companies (AA25-141A)
- Response to CISA Advisory (AA25-141A)
- Russian Unit 26165 Targets Western Logistics and Technology Companies
- US CERT Alert AA25-141A: SafeBreach Coverage
- Detect APT28 Attacks: Russian GRU Unit 26165 Targets Western Logistics and Technology Companies Coordinating Aid to Ukraine
- Rheinmetall: US and Germany foiled Russian plot to assassinate Armin Papperger CEO
- Foiled Assassination Plot on Rheinmetall CEO Armin Papperger
- Russian secret services plotted assassination of German drone manufacturer chief
- The throwaway agents Moscow sent after a Bavarian drone boss arming Ukraine—and how Germany stopped them
- Germany Thwarts Russian Plot to Assassinate Executive of Donaustahl, Drone Supplier to Ukraine
- 'Potential targets': Russia threatens European firms producing drones for Ukraine
- Russia's Defense Ministry publishes list of European drone manufacturers, and a Kremlin official calls them potential military targets
- Medvedev to help: The Poles found two of their cities in the list of targets of the Ministry of Defense
- Russia's Shadow War Against the West
Threats related to Russia (GRU Unit 26165 / APT28) Runs Multi-Vector
Detection coverage for TL-2026-2031
As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2031 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.