TechForge

September 6, 2024

Another day, another instance of those crazy Russian hackers. A joint body of US security agencies has identified a unit of the GRU (the Russian General Staff Main Intelligence Directorate) responsible for cyber attacks against multiple organisations worldwide, with its findings published in a joint cybersecurity advisory document.

The Russian 161st Specialist Training Center is known internally as Unit 29155, a group of skilled cybersecurity personnel that is used by the Russian state “for the purposes of espionage, sabotage, and reputational harm,” according to the joint advisory. Active since at least 2020, the unit has been held responsible for attempted coups, sabotage and “influence operations” in Europe, including activities to further Russian military actions in Ukraine, according to assessments made by the FBI, NSA and CISA (Federal Bureau of Investigations, National Security Agency and the Cybersecurity and Infrastructure Security Agency) in the paper.

In addition to multiple attacks against Ukrainian government targets since 2022 which have used the WhisperGate malware, Unit 29155 has attacked numerous critical targets in member states of NATO (North Atlantic Treaty Organization), resulting in data leaks and website content corruption. Exfiltrated data from attacks is either ransomed or released on public forums.

The FBI states it has observed more than 14,000 cases of domain scanning in at least 26 NATO countries and other EU states. The joint cybersecurity advisory paper claims Unit 29155’s targets include government services, the financial sector and infrastructure such as healthcare, energy and transport.

The tactics used are relatively standard, comprising reconnaissance and exploitation of vulnerabilities using publicly-available CVE (critical vulnerabilities and exposures) exploit scripts hosted on GitHub. The scripts have been used to target known vulnerabilities in Microsoft Windows Server and Active Directory, Atlassian’s Confluence Server, Sophos’ Firewall and Red Hat privilege management software such as polkit.

The joint advisory notes that, “Rather than build custom solutions, Unit 29155 cyber actors use common red teaming techniques and publicly available tools to conduct [its] cyber operations.” The ubiquity of the techniques and methods used in the unit’s activities has led to attacks being misattributed to the group or the group’s attacks being unidentified or placed at the door of other parties.

The unit’s known names are thought to be, among others, Cadet Blizzard, Ember Bear (also known as Bleeding Bear), Frozenvista and the less snappily-moniker-ed but equally effective UNC2589 and UAC-0056.

Unit 29155 seems to have prioritised its attention on IP address ranges used by governments and organisations running critical infrastructure. The deployed reconnaisance tools are easily available and include several that are included in common computer operating systems.

The availability of the tools used by Unit 29155, similar groups and individuals is not, as of itself, a security lapse. Rather, it is the malicious way such tools are used, combined with lax (or no) security measures placed by victims. Responsibility for poor security is spread between hardware manufacturers, firmware and software providers, and most of all, any technology’s end-users themselves.

By not taking the most basic of precautions (such as changing the default passwords of networked devices), organisations place themselves firmly in the category of ‘low-hanging fruit’ and are open to cyber exploits that are relatively trivial to perform. The activities of Unit 29155 detailed in the joint advisory paper do not comprise a list of cunning new zero-day (new or previously unknown) hacks but instead read like an average cybersecurity training manual. By not responding to known security vulnerabilities or being unaware of them, victims’ systems are needlessly open to exploitation.

An example given in the paper is the presence of unprotected CCTV cameras placed with public-facing IP addresses that are compromised and used as a base for further penetration into the rest of an organisation’s network.

While no one is safe from new and emerging threat vectors, it is incumbent on operators of critical infrastructure and government organisations to secure their systems in accordance with known remediations and prophylactics. While the nature of Unit 29155 and its aims may be abhorrent to many readers, the group itself and its methods are by no means unique. Cybercrime is largely opportunistic, and the identity of the perpetrators is usually moot from the victim’s standpoint.

Author

  • Joe Green

    Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

    View all posts

About the Author

Joe Green

Joe Green is a writer based in Bristol, UK. He acquired his first Mac and dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)