Russia's military intelligence service, the GRU, has been systematically hacking internet-connected home security cameras, smart doorbells, companies and even bank accounts belonging to unsuspecting citizens in 13 NATO member states, including Greece.
According to reports, the objective is to gather intelligence on the movement of military equipment and officials.
The picture of Russia's cyber operations is becoming increasingly clear as investigators uncover cybercrime networks operating from Russia. Evidence suggests Moscow has developed an extensive hybrid warfare network targeting Western countries, including hacking groups that steal banking credentials through phishing attacks, deploy ransomware to lock files and demand payment, and carry out a range of other online scams.
Investigations by US and European intelligence agencies, together with the joint cybersecurity body CSA, indicate that the Russian state has financed and organised a cyber campaign targeting Western logistics businesses, technology companies and private households.
The campaign has been running since 2022 and is being conducted by Unit 26165 of the Russian military intelligence service, the GRU. The unit is officially known as the 85th Main Special Service Centre and operates under numerous aliases depending on the nature of its missions.
Mix of cyber tactics
According to CSA findings, Russian hackers have focused on logistics and technology companies, employing a mix of tactics, techniques and procedures, including reconstructed password-spraying capabilities, spear-phishing attacks and the modification of access permissions for Microsoft Exchange mailboxes.
Cybersecurity agencies believe these practices and targeting efforts remain ongoing.
According to US and European intelligence and cybersecurity services, GRU Unit 26165, known within the cybersecurity community as APT28, Fancy Bear, Forest Blizzard, BlueDelta and several other names, has been carrying out this campaign for more than two years.
Targets across NATO countries
The report states that the cyber operation conducted by GRU Unit 26165 against Western logistics providers and technology firms has targeted dozens of organisations, including government agencies and private-sector entities involved in nearly every mode of transport, including air, maritime and rail networks.
The group has targeted organisations operating in NATO member states, Ukraine and international organisations across sectors including:
- Defence industry
- Transport and transport hubs, including ports and airports
The intelligence findings suggest that the operation is aimed at collecting information that could assist Russia in monitoring logistics chains, military movements and strategic infrastructure across Western countries.
Source: protothema.gr


