/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

NSA and FBI say Russian state sponsored hacker group Fancy Bear is using a previously undisclosed Linux malware called Drovorub for cyber espionage operations

my favorite thing so far: NSA casually reveals that Drovorub is the codename used by GRU itself (!), and even offers a step-by-step translation https://www.nsa.gov/... https://twitter.com/... @us_cybercom : Today, the USG exposed a GRU 85th cyber espionage tool. Tools like this are hidden from operating systems & are expensive to engineer/maintain, w/ actors often using for the most valuable targets. Mitigating against it will cost Russian military intelligence time, money, & access https://twitter.com/... Secretary Pompeo / @secpompeo : Russia's malicious cyber activity threatens the security of the U.S. and our partners. By following the mitigation steps in the @NSAGov and @FBI advisory, Americans and our friends can better protect ourselves from Russian malware and counter Russia's cyber capabilities. https://twitter.com/... Andrew Thompson / @anthomsec : Straight to the point. Impose cost. https://twitter.com/... Random Facts Girl / @soychicka : Targeting Linux. 🤨 https://twitter.com/... Yoshi / @chicagocyber : Releasing something detailed publicly likely took a herculean bureaucratic effort. Kudos to the authors. If you liked the level of detail, let them know next time you're at Infragard or talking to your local agent. https://twitter.com/... @fbi : The #FBI and @NSAGov have released a cybersecurity advisory about a malware known as Drovorub. Russia's military intelligence unit created Drovorub to target customers who use Linux systems. https://ow.ly/... https://twitter.com/... @780thc : The Russian General Staff Main Intelligence Directorate 85th Main Special Service Center, military unit 26165, is deploying previously undisclosed malware for Linux systems, called Drovorub, as part of its cyber espionage operations. @RT_com https://media.defense.gov/... Andy Greenberg / @a_greenberg : On top of disrupting some Russian hacking, this is another data point to distinguish GRU hacking groups: It makes clearer that Fancy Bear/APT28 is indeed GRU Unit 26165, distinct from those other GRU hackers, Sandworm, already confirmed to be Unit 74455. https://www.nsa.gov/...

CyberScoop Shannon Vavra

Context & Ripple Effects

This advisory lands weeks after reporting on Fancy Bear's broad campaign against US targets running from December 2018 into May 2020 — but it goes further than typical threat reporting by using the GRU's own internal codename for the tool and publishing detection guidance directly. That choice signals the exposure is meant to burn the capability, not just document it.

It also extends an attribution pattern the corpus keeps filling in: Fancy Bear tied to GRU Unit 26165 here, and later disclosures mapping other units like the one behind Cadet Blizzard. The NSA-FBI pairing on a Linux implant matters because most enterprise hunting at the time centered on Windows endpoints.

First-order effects

  • Linux administrators at US government and critical-infrastructure organizations gain concrete detection signatures for Drovorub and must sweep their fleets immediately, since the malware was built to hide from the operating system.
  • GRU Unit 26165 loses a high-cost espionage implant on its most valuable targets — US Cybercom framed mitigation as costing Russian military intelligence time, money, and access.

Second-order effects

  • Fancy Bear is pushed onto replacement tooling, a shift visible a year later when the same NSA-FBI coalition flagged the group running brute-force attacks through Kubernetes clusters against US and foreign organizations.
  • Defenders broaden their monitoring posture toward Linux servers and cloud infrastructure, raising the engineering bar for any state actor whose implants assumed unmonitored Unix environments.

Third-order effects

  • Public 'name-and-shame' disclosure hardens into standing US counterintelligence doctrine: agencies now routinely burn specific GRU units and tools, forcing Russian military intelligence into a costly rebuild cycle between operations rather than long-lived access.
  • As unit-level attribution accumulates across disclosures, pressure builds for policy responses that treat these named units as fixed targets — while the line between state tradecraft and commercial spyware continues to blur, as Google's finding that APT29 exploits resemble Intellexa and NSO Group tooling suggests.

The trend: US cyber agencies are systematically exposing Russian military intelligence tooling and unit structure, turning public disclosure into a weapon that forces GRU operators to constantly re-engineer their access.

Discussion

  • @nsacyber @nsacyber on x
    The Russian GRU 85th GTsSS, sometimes publicly known as #APT28 or #FancyBear, is using a previously undisclosed #Linux malware called Drovorub for cyber espionage operations. For full details and mitigations, review our #cybersecurity advisory with @FBI: https://www.nsa.gov/... h…
  • @ridt Thomas Rid on x
    The level of detail in today's NSA/FBI advisory is truly stunning—my favorite thing so far: NSA casually reveals that Drovorub is the codename used by GRU itself (!), and even offers a step-by-step translation https://www.nsa.gov/... https://twitter.com/...
  • @us_cybercom @us_cybercom on x
    Today, the USG exposed a GRU 85th cyber espionage tool. Tools like this are hidden from operating systems & are expensive to engineer/maintain, w/ actors often using for the most valuable targets. Mitigating against it will cost Russian military intelligence time, money, & access…
  • @secpompeo Secretary Pompeo on x
    Russia's malicious cyber activity threatens the security of the U.S. and our partners. By following the mitigation steps in the @NSAGov and @FBI advisory, Americans and our friends can better protect ourselves from Russian malware and counter Russia's cyber capabilities. https://…
  • @anthomsec Andrew Thompson on x
    Straight to the point. Impose cost. https://twitter.com/...
  • @soychicka Random Facts Girl on x
    Targeting Linux. 🤨 https://twitter.com/...
  • @chicagocyber Yoshi on x
    Releasing something detailed publicly likely took a herculean bureaucratic effort. Kudos to the authors. If you liked the level of detail, let them know next time you're at Infragard or talking to your local agent. https://twitter.com/...
  • @fbi @fbi on x
    The #FBI and @NSAGov have released a cybersecurity advisory about a malware known as Drovorub. Russia's military intelligence unit created Drovorub to target customers who use Linux systems. https://ow.ly/... https://twitter.com/...
  • @780thc @780thc on x
    The Russian General Staff Main Intelligence Directorate 85th Main Special Service Center, military unit 26165, is deploying previously undisclosed malware for Linux systems, called Drovorub, as part of its cyber espionage operations. @RT_com https://media.defense.gov/...
  • @a_greenberg Andy Greenberg on x
    On top of disrupting some Russian hacking, this is another data point to distinguish GRU hacking groups: It makes clearer that Fancy Bear/APT28 is indeed GRU Unit 26165, distinct from those other GRU hackers, Sandworm, already confirmed to be Unit 74455. https://www.nsa.gov/...