WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) Russian GRU Targeting Western Logistics Entities and Technology Companies
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) Russian GRU Targeting Western Logistics Entities and Technology Companies

TLP:CLEAR

Author: Chase Snow

Created: Thursday, May 22, 2025 - 15:09

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: A joint Cybersecurity Advisory (CSA) was just released by over 20 federal and international partner agencies to highlight a Russian state-sponsored campaign targeting Western logistics entities and technology companies. The CSA provides an overview of targets, initial access tactics, techniques, and procedures (TTPS), and indicators of compromise (IOCs) that are associated with the campaign.

Analyst Note: The CSA reports that since 2022, western logistics entities and IT companies have faced an elevated risk of targeting by the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165. WaterISAC is sharing for member awareness.

Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a

Related WaterISAC PIRs: 6.1, 7, 7.1, 10, 11

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar