The British government and its international allies have for the first time exposed a Russian military unit responsible for cyberattacks and digital sabotage. This revelation highlights the growing threat of state-sponsored cybercrime and the need for increased security measures.

Important findings

  • The UK and 9 international allies have exposed Russian military actors for computer network operations aimed at espionage, sabotage and reputational damage.
  • GRU Unit 29155 has expanded its methods to conduct offensive cyber operations and deploy Whispergate malware against victim organisations in Ukraine.
  • UK organisations are encouraged to follow the advice to defend themselves against online threats.

Joint advisory from the UK and its allies

In a new joint advisory, the National Cyber Security Centre (NCSC), part of GCHQ, and agencies in the USA, the Netherlands, the Czech Republic, Germany, Estonia, Latvia, Canada, Australia and Ukraine have revealed the tactics and techniques used by Unit 29155 of Russia’s GRU to conduct global cyber operations.

Unit 29155 is suspected of targeting organizations to collect information for espionage purposes, cause reputational damage by stealing and leaking sensitive information, deface victim websites, and engage in systematic sabotage by destroying data.

First Public Disclosure of Unit 29155

It is the first time that the UK has publicly exposed Unit 29155, also referred to as the 161st Special Training Centre, as responsible for malicious cyber activity it has conducted at least since 2020.

Since 2022, the main objective of the group appears to be to disrupt efforts in support of Ukraine. Today, the UK and its allies can confirm that it was specifically Unit 29155 that used the Whispergate malware against several victims in Ukraine before the Russian invasion in 2022.

Recommendations for countering cyber threats

To prevent these malicious activities from affecting UK organisations, the NCSC strongly advises network defenders to follow the recommended guidance measures to strengthen their cyber resilience.

Paul Chichester, Director of Operations at NCSC, said:

"The exposure of Unit 29155 as a capable cyber actor demonstrates the importance Russian military intelligence attaches to cyberspace in pursuing its illegal war in Ukraine and other state priorities.

The UK, together with our partners, is determined to denounce Russian malicious cyber activity and will continue to do so.

The NCSC strongly encourages organisations to follow the mitigation recommendations and guidance included in the advisory to defend their networks."

Cooperation with international partners

The advisory states that the unit, which consists of young active GRU officers, also relies on non-GRU actors, including known cybercriminals and supporters, to carry out its operations. The group differs from the more established GRU-related cyber groups Unit 26165 (Fancy Bear) and Unit 74455 (Sandworm).

The NCSC has previously revealed details of malware operations used by Russian military intelligence cyber actors to target the Ukrainian military, and also called on organizations to take action after Russia’s attack on Ukraine.

In May 2022, the UK and its allies attributed the use of Whispergate malware in Ukraine to Russian military intelligence, but this new advisory goes further by attributing its use specifically to Unit 29155.

The advisory also includes further analysis of the malware used to help network defenders identify malicious infrastructure.

Sources

  • UK and allies uncover Russian military unit carrying out… – NCSC.GOV.UK, National Cyber Security Centre.