From December 2018 to May of this year, Russia's GRU hacker group known as APT 28 or Fancy Bear has carried out a broad campaign against a range of US targets
A previously unreported Fancy Bear campaign persisted for well over a year—and indicates that the notorious group has broadened its focus. Tweets: @anthomsec , @wired , @dragosinc , @robertmlee , @a_greenberg , and @780thc Tweets: Andrew Thompson / @anthomsec : “There is an expectation of continued activity.” Advanced can be described as multifaceted orchestration of disparate resources in furtherance of unified objectives (My words). Persistent can be described as unrelenting-continued-enduring- forever. Threat = Capability and Intent. https://twitter.com/... @wired : Russia's GRU military intelligence agency has carried out many of the most aggressive hacking acts in history: Destructive worms, blackouts, and a broad operation designed to influence the 2016 election. Now it appears the GRU is hitting US networks again. https://www.wired.com/... @dragosinc : Dragos Principal Adversary Hunter @jfslowik provides insights into #APT28, known to target critical US infrastructure. Read more from @Wired here: https://www.wired.com/... Robert M. Lee / @robertmlee : Interesting to watch and good quote by @DragosInc's. @jfslowik - targeting of energy infrastructure is unfortunately common but not panic inducing. But a possible Sandworm connection puts extra emphasis on the need to be vigilant. https://twitter.com/... Andy Greenberg / @a_greenberg : We obtained an FBI notification to hacking victims sent out in May. It reveals that the Russian GRU hackers known as Fancy Bear or APT28 have been targeting US state and federal agencies, educational institutions and the US energy sector. https://www.wired.com/... @780thc : According to an FBI notification, from December 2018 until at least May of this year, the GRU hacker group known as APT28 or Fancy Bear carried out a broad hacking campaign against US targets. @RT_com @RT_America #cyber https://www.wired.com/...
Context & Ripple Effects
This July 2020 Wired report, based on work by Dragos' Robert M. Lee and Andy Greenberg, documented a previously unreported Fancy Bear campaign that ran from December 2018 through May 2020 against US state and federal agencies, educational institutions, and the energy sector — a target list notably broader than the election-focused operations the GRU unit was known for. Weeks later, the NSA and FBI disclosed the Drovorub Linux malware used in that espionage work, turning this report into the first public layer of a sustained unmasking effort.
The arc since has been consistent: agencies followed with warnings that Fancy Bear was abusing Kubernetes clusters for brute-force attacks from mid-2019, and in 2024 the US and its allies disrupted APT28's access to 1,000+ hijacked home and small-business routers. The throughline is a GRU unit whose operations outlast any single disclosure, with Andrew Thompson's reported note that there is 'an expectation of continued activity' proving accurate across four years of follow-on coverage.
First-order effects
- US state and federal agencies, universities, and energy-sector operators named in the campaign face an adversary that treats disclosure as a speed bump, not a stop sign — the activity ran undetected for over 18 months before this report.
- Dragos' involvement signals the energy targeting touched industrial control environments, putting OT defenders — not just IT security teams — on alert for GRU intrusion tradecraft.
Second-order effects
- The NSA, FBI, and allied partners were pushed into an escalating response cadence: malware advisories (Drovorub), technique warnings (the Kubernetes brute-force campaign), and eventually offensive disruption of APT28's router infrastructure — each disclosure a direct counter to the persistence documented here.
- Attribution pressure spread across the GRU's portfolio: the same allied coalition later tied Cadet Blizzard to GRU Unit 29155, forcing Russia to spread operations across multiple units rather than concentrating them under the Fancy Bear brand.
Third-order effects
- If the pattern holds, state-sponsored intrusion campaigns become multi-year infrastructure problems rather than incident-response events — the countermeasure shifts from patching after disclosure to preemptive takedowns of adversary access infrastructure, as the 2024 router operation demonstrated.
- The GRU's structure is consolidating into distinct units with overlapping cyber mandates (Fancy Bear, Sandworm, Cadet Blizzard/Unit 29155), meaning defenders must now track organizational churn inside Russian military intelligence as closely as the malware itself.
The trend: GRU cyber operations are broadening in target scope and persistence while US and allied agencies shift from passive attribution to active, repeated disruption of Russian state hacking infrastructure.