ctipilot.ch
← Back to Weekly 2026-W33
NOTABLENATOB2research

Russia's campaign against Europe's Ukraine defence supply chain is assessed to have widened from collection and sabotage to pressuring the people and firms behind it — and the cyber half is aimed at logistics data, not at the manufacturers

discovered 2026-08-16 23:59 UTCrun 2026-08-16T2315Z-weekly1 sourcesingle-source

Truesec's 14 August assessment gathers separately-reported European incidents into a single campaign picture. In late 2025 and early 2026 German authorities were reportedly investigating surveillance of the chief executive of the drone manufacturer Donaustahl and his family; in 2024 US intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall's chief executive; Russia published the addresses of European drone producers, which Truesec assesses as "target signalling: intimidation, information operations and possible enabling of future targeting by sympathizers or recruited proxies" rather than as disclosure of anything. Set against that physical-domain activity, the cyber half is narrower and more concrete: "GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. Observed GRU-linked activity included attempts to access shipment-related information such as train schedules, manifests, routes, cargo contents and sender/recipient details" (Truesec, 2026-08-14). Truesec attributes the attribution itself: "In the cyber and logistics campaign, Western authorities have specifically attributed activity to GRU Unit 26165, while the Donaustahl reporting refers more broadly to Russian intelligence services," pointing at an April 2026 joint advisory from CISA, the NSA, the FBI and NCSC UK.

The horizon judgement is the reason to record it. Truesec's assessment is that the campaign's focus "is no longer limited to intelligence collection, sabotage or disruption of logistics" and now reaches the people, facilities and supply chains that make European defence support to Ukraine possible — with the operating model combining state-led intelligence targeting with recruited low-level agents who are not trained intelligence officers.

Triage: collection against shipment data looks like ordinary business use of the same systems, so the discriminators are account context and breadth rather than the access itself. The shapes worth separating from routine operations are a single account querying or exporting consignment records far outside its normal customer or route scope, retrieval of historical manifests with no matching operational request, and searches of document repositories or mailboxes keyed to route, cargo or counterparty terms by accounts that do not perform that role. Legitimate freight and customs work is narrow and tied to a live consignment; bulk retrieval across counterparties and time is not. Where an intrusion is suspected, the personnel dimension is part of the scope: mailbox and directory access touching staff whose work is publicly linked to defence customers.

GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. Observed GRU-linked activity included attempts to access shipment-related information such as train schedules, manifests, routes, cargo contents and sender/recipient details.

The focus is no longer limited to intelligence collection, sabotage or disruption of logistics.

In the cyber and logistics campaign, Western authorities have specifically attributed activity to GRU Unit 26165, while the Donaustahl reporting refers more broadly to Russian intelligence services.

Truesec 2026-08-14

ATT&CK mapping

5 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Reconnaissance TA0043
T1589Gather Victim Identity Information

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.

overlap matrix · ATT&CK page ↗

T1591Gather Victim Org Information

Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisions/departments, specifics of business operations, as well as the roles and responsibilities of key employees.

overlap matrix · ATT&CK page ↗

T1591.002Gather Victim Org Information: Business Relationships

Adversaries may gather information about the victim's business relationships that can be used during targeting. Information about an organization’s business relationships may include a variety of details, including second or third-party organizations/domains (ex: managed service providers, contractors, etc.) that have connected (and potentially elevated) network access. This information may also reveal supply chains and shipment paths for the victim’s hardware and software resources.

overlap matrix · ATT&CK page ↗

Collection TA0009
T1005Data from Local System

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

overlap matrix · ATT&CK page ↗

T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.