The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020.
GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455.
Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division
Related:
- Blinder Tunnel Campaign Targets Iraqi Infrastructure
October 6, 2026
Palo Alto Unit 42 discovered that an Iranian state-aligned threat actor has been masquerading as the Dubai Airports IT department to deliver trojanized coding challenges to high-value targets. Unit 42 tracks the activity as CL-STA-1178. This activity includes a campaign they call “Blinder Tunnel,” that targeted Iraqi critical infrastructure in March 2026, following infrastructure staging ...
- Hackers access data of 8.8 million people in Denmark in ‘extremely serious’ breach
October 5, 2026
A major cybersecurity breach has exposed the personal data of 8.8 million people in Denmark. Denmark has suffered a major data breach after hackers broke into the country’s national population registry and accessed the personal information of millions of people. The country’s digital affairs minister announced the data breach on Monday, calling it “an extremely serious incident” ...
- ShinyHunters hacker in FBI data theft detained in Jordan, cooperating with bureau
October 3, 2026
A suspected member of the ShinyHunters hacking group, which says it stole data on every FBI employee, was detained in Jordan this week and is cooperating with the FBI, three people familiar with the matter told Reuters. Saif al-Din Khader was detained by Jordanian authorities, the three sources said. Two of them said he was brought ...
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
October 2, 2026
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet’s email security platform. Fortinet describes the vulnerability as a combination of path traversal and ...
- SMTP is the key: BPFDoor and AVERAT hitting the network edge
October 2, 2026
Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant Rapid7 researchers track as AVERAT, deployed against Taiwanese ...
- Operation KillSwitch: Teenager suspected of leading KillSec ransomware group
October 1, 2026
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of stolen files unless they paid a ransom. The action was part of Operation KillSwitch, an international investigation led by German ...
