Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain — Threadlinqs Intelligence
As of 2026-08-16, Russia (GRU Unit 26165 / APT28) Runs Multi-Vector Surveillance, Intimidation, Sabotage and Cyber Espionage Campaign Against Europe's Ukraine Defence Supply Chain is a high-severity supply chain threat attributed to GRU Unit 26165 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 14 indicators of compromise.
Threat ID: TL-2026-2031 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: GRU Unit 26165 · Russia · ESPIONAGE
Truesec documents a sustained Russian intelligence campaign — GRU Unit 26165 (85th GTsSS, aka APT28/Fancy Bear/Forest Blizzard/BlueDelta) for cyber and logistics-targeting operations — combining
Since 2022, GRU Unit 26165 (Russia's General Staff Main Intelligence Directorate, 85th Main Special Service Center / GTsSS, publicly tracked as APT28, Fancy Bear, Forest Blizzard and BlueDelta) has run a multi-year, multi-vector campaign against the European supply chain sustaining Ukraine's defence. Truesec's August 2026 report ties together three converging lines of activity attributed to Russian state intelligence.
First, physical surveillance and intimidation of defence-industry executives: German investigators (per Die Zeit) allege that a Ukrainian national (Serhii N.) and a Romanian national (Alla S.), operating as recruited 'disposable' agents contacted via Telegram, filmed and photographed the home and headquarters of Donaustahl CEO Stefan Thumann between December 2025 and March 2026, with both arrested in a coordinated Spain/Germany operation in March 2026 and charged with acting as agents of a foreign intelligence service. This mirrors the pattern behind the July 2024 plot against Rheinmetall CEO Armin Papperger, in which US intelligence warned German authorities in time to disrupt an assassination attempt tied to Rheinmetall's build-out of an armoured-vehicle plant in Ukraine.
Second, a documented cyber-espionage program: CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A (May 2025, building on an April 2026 follow-on advisory referenced by Truesec) attributes a two-year campaign by Unit 26165 against Western logistics entities and technology companies coordinating the transport and delivery of Ukraine aid. Initial access combined credential guessing/brute forcing (routed through Tor and compromised SOHO routers/VPNs for anonymization), targeted spearphishing in the recipient's local language, and exploitation of known vulnerabilities in Microsoft Outlook (CVE-2023-23397, forced NTLM authentication leak), WinRAR (CVE-2023-38831, archive content-type spoofing) and Roundcube webmail (CVE-2021-44026, CVE-2020-35730, CVE-2020-12641). Post-compromise activity used the HEADLACE credential-phishing/LNK-dropper backdoor, the Python-based MASEPIE file-transfer/remote-access tool, and the OCEANMAP and STEELHOOK backdoors; persistence via scheduled tasks, registry Run keys/startup-folder LNK files and Exchange mailbox-permission abuse; defense evasion via Windows Event Log clearing (wevtutil); credential access via NTDS.dit extraction, GPP password recovery and Certipy ADCS abuse; lateral movement via RDP, Impacket WMIEXEC and PAExec; and exfiltration of .pst/.ost mail archives and shipment manifests over encrypted mail protocols, custom OpenSSH binaries and, in some cases, abused third-party webhook-relay services (webhook.site, pipedream.net, mockbin.org) as low-noise C2/exfil relays. A related, tactically linked sub-campaign hijacked internet-facing IP cameras at logistics sites and border crossings via crafted RTSP requests and brute-forced credentials — over 80% of targeted cameras in Ukraine, with a high concentration also in Romania and Poland — to visually track aid-shipment movements, feeding the same targeting picture used for the physical operations.
Third, sabotage and information-operations pressure: CSIS's March 2025 'Russia's Shadow War Against the West' dataset recorded Russian-linked arson/explosive incidents in Europe rising from 1 in 2023 to 26 in 2024 (at least 6 more in 2025), roughly 28% against transportation targets and 28% against government targets; incidents tied to the same actor set include a May 2024 arson at a Berlin Diehl Group munitions-linked facility and explosives intercepted at the Serbian-Hungarian border in June 2026 in a truck bound for Bavaria, where investigators have not ruled out a second executive-targeting plot. In April 2026, Russia's Ministry of Defence published two target lists — 'Branches of Ukrainian Companies in Europe' (11 sites) and 'Foreign Enterprises Producing Components' (10 sites) — naming drone and component manufacturers across 12 countries, after which Medvedev state
Weaknesses (CWE)
CWE-294, CWE-20, CWE-345, CWE-351
Target sectors: defense, government administration, logistics, technology, manufacturing, critical infrastructure
Target regions: germany, united kingdom, spain, italy, poland, israel, netherlands, denmark, latvia, lithuania, czechia, Turkiye
Timeline
- GRU Unit 26165 begins expanding cyber-espionage targeting of Western logistics entities and technology companies involved in coordinating Ukraine aid delivery, per CISA/NSA/FBI/NCSC-UK joint advisory AA25-141A.
- Arson at a Berlin factory owned by the Diehl Group, suspected by Western officials to be Russian sabotage aimed at disrupting arms-delivery supply chains to Ukraine.
- US intelligence warns German authorities of a Russian plot to assassinate Rheinmetall CEO Armin Papperger; German security services disrupt the plot and increase his protection.
- CSIS publishes 'Russia's Shadow War Against the West,' documenting a near-tripling of Russian-linked sabotage/subversion incidents in Europe between 2023 and 2024 (1 to 26 arson/explosive incidents), with transportation and government sectors most targeted.
- CISA, NSA, FBI and international partners issue joint cybersecurity advisory AA25-141A detailing GRU Unit 26165's two-year cyber-espionage campaign against Western logistics and technology firms, including IP-camera hijacking at Ukrainian border crossings.
- Two agents recruited by Russian intelligence begin physical surveillance of Donaustahl CEO Stefan Thumann's home and company headquarters (period runs through March 2026), per Die Zeit.
- German and Spanish law enforcement arrest the two agents (a Ukrainian national and a Romanian national) surveilling the Donaustahl CEO in a coordinated operation; Germany's Federal Prosecutor charges both as agents of a foreign intelligence service.
- Russia's Ministry of Defence publishes two lists naming 21 European drone-production and component-manufacturing sites across 12 countries, including 'Branches of Ukrainian Companies in Europe' and 'Foreign Enterprises Producing Components.'
- Russian Security Council Deputy Chairman Dmitry Medvedev states on X that the Ministry of Defence's published site list 'must be taken literally' as 'a list of potential targets for the Russian armed forces,' explicitly threatening kinetic strikes.
- Explosives are discovered at the Serbian-Hungarian border in a truck heading to Bavaria, Germany; investigators do not rule out preparation for another attack on a German defense-industry executive. Two suspects arrested with confirmed contacts to Russian intelligence representatives.
- Truesec publishes a consolidated report tying the physical surveillance, sabotage, cyber-espionage and public-intimidation threads together as a single coordinated Russian campaign against Europe's Ukraine defence supply chain.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 14 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, CVE-2023-23397, CVE-2023-38831, CVE-2021-44026, CVE-2020-35730, CVE-2020-12641, T1589, T1566, T1190, T1133, T1204, T1547, T1053, T1098, T1110, T1187