CyberThreat Report

CyberThreat Report

Share this post

CyberThreat Report
CyberThreat Report
The Digital Claws of the GRU: Fancy Bear's Operations in Cyberspace
Copy link
Facebook
Email
Notes
More
English

The Digital Claws of the GRU: Fancy Bear's Operations in Cyberspace

Over the past three years, Russian APT28 (also known as Fancy Bear) has fine-tuned its cyber weapons and reshaped the digital battlefield through targeted attacks.

Katalin Béres's avatar
Ferenc Frész's avatar
Katalin Béres
and
Ferenc Frész
Feb 06, 2025
∙ Paid
1

Share this post

CyberThreat Report
CyberThreat Report
The Digital Claws of the GRU: Fancy Bear's Operations in Cyberspace
Copy link
Facebook
Email
Notes
More
1
Share

Cyber warfare has played an increasingly significant role in geopolitical conflicts in recent years, especially since the outbreak of the Russian-Ukrainian war.

APT28 - also known as Fancy Bear, Sofacy, or STRONTIUM - linked to Russian military intelligence (GRU, Military Unit 26165) is one of the most well-known and active state-sponsored hacker groups, closely tied to Russian military and geopolitical interests for more than 20 years.

This group not only conducts classical cyber espionage but has also become a key player in modern information warfare and cyber warfare. APT28's objectives include gathering intelligence, political influence operations, and weakening adversaries' critical infrastructure.

APT28 is therefore not simply a hacker group, but a well-organized cyber warfare unit that fits into military structure, continuously evolving and serving as a key player in the war being waged in cyberspace.

In a recently published analysis1, Maverits examined the activities of this group, APT28, between 2022 and 2024. It's worth noting that the cybersecurity firm conducting the analysis is headquartered in Ukraine, maintaining close ties with Ukrainian national security and defense organizations. This geographical and operational position enabled the report to rely on the most current and in-depth information possible.

The article aims to summarize the key findings of the Maverits report and place them in a broader context, demonstrating how APT28's activities fit into Russian military-diplomatic strategy and global cyber warfare trends.


APT28's Target Countries and Geopolitical Objectives

APT28's activities have always been closely tied to Russia's geopolitical interests. However, in the past three years, the group's geographical focus of attacks has somewhat shifted as a consequence of the war that broke out in 2022. The analysis of target countries not only shows where APT28 is active, but

Keep reading with a 7-day free trial

Subscribe to CyberThreat Report to keep reading this post and get 7 days of free access to the full post archives.

Already a paid subscriber? Sign in
© 2025 CyEx Kft.
Publisher Privacy
Substack
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture

Share

Copy link
Facebook
Email
Notes
More