NSA and FBI say Russian state sponsored hacker group Fancy Bear is using a previously undisclosed Linux malware called Drovorub for cyber espionage operations
my favorite thing so far: NSA casually reveals that Drovorub is the codename used by GRU itself (!), and even offers a step-by-step translation https://www.nsa.gov/... https://twitter.com/... @us_cybercom : Today, the USG exposed a GRU 85th cyber espionage tool. Tools like this are hidden from operating systems & are expensive to engineer/maintain, w/ actors often using for the most valuable targets. Mitigating against it will cost Russian military intelligence time, money, & access https://twitter.com/... Secretary Pompeo / @secpompeo : Russia's malicious cyber activity threatens the security of the U.S. and our partners. By following the mitigation steps in the @NSAGov and @FBI advisory, Americans and our friends can better protect ourselves from Russian malware and counter Russia's cyber capabilities. https://twitter.com/... Andrew Thompson / @anthomsec : Straight to the point. Impose cost. https://twitter.com/... Random Facts Girl / @soychicka : Targeting Linux. 🤨 https://twitter.com/... Yoshi / @chicagocyber : Releasing something detailed publicly likely took a herculean bureaucratic effort. Kudos to the authors. If you liked the level of detail, let them know next time you're at Infragard or talking to your local agent. https://twitter.com/... @fbi : The #FBI and @NSAGov have released a cybersecurity advisory about a malware known as Drovorub. Russia's military intelligence unit created Drovorub to target customers who use Linux systems. https://ow.ly/... https://twitter.com/... @780thc : The Russian General Staff Main Intelligence Directorate 85th Main Special Service Center, military unit 26165, is deploying previously undisclosed malware for Linux systems, called Drovorub, as part of its cyber espionage operations. @RT_com https://media.defense.gov/... Andy Greenberg / @a_greenberg : On top of disrupting some Russian hacking, this is another data point to distinguish GRU hacking groups: It makes clearer that Fancy Bear/APT28 is indeed GRU Unit 26165, distinct from those other GRU hackers, Sandworm, already confirmed to be Unit 74455. https://www.nsa.gov/...
Context & Ripple Effects
This advisory lands weeks after reporting on Fancy Bear's broad campaign against US targets running from December 2018 into May 2020 — but it goes further than typical threat reporting by using the GRU's own internal codename for the tool and publishing detection guidance directly. That choice signals the exposure is meant to burn the capability, not just document it.
It also extends an attribution pattern the corpus keeps filling in: Fancy Bear tied to GRU Unit 26165 here, and later disclosures mapping other units like the one behind Cadet Blizzard. The NSA-FBI pairing on a Linux implant matters because most enterprise hunting at the time centered on Windows endpoints.
First-order effects
- Linux administrators at US government and critical-infrastructure organizations gain concrete detection signatures for Drovorub and must sweep their fleets immediately, since the malware was built to hide from the operating system.
- GRU Unit 26165 loses a high-cost espionage implant on its most valuable targets — US Cybercom framed mitigation as costing Russian military intelligence time, money, and access.
Second-order effects
- Fancy Bear is pushed onto replacement tooling, a shift visible a year later when the same NSA-FBI coalition flagged the group running brute-force attacks through Kubernetes clusters against US and foreign organizations.
- Defenders broaden their monitoring posture toward Linux servers and cloud infrastructure, raising the engineering bar for any state actor whose implants assumed unmonitored Unix environments.
Third-order effects
- Public 'name-and-shame' disclosure hardens into standing US counterintelligence doctrine: agencies now routinely burn specific GRU units and tools, forcing Russian military intelligence into a costly rebuild cycle between operations rather than long-lived access.
- As unit-level attribution accumulates across disclosures, pressure builds for policy responses that treat these named units as fixed targets — while the line between state tradecraft and commercial spyware continues to blur, as Google's finding that APT29 exploits resemble Intellexa and NSO Group tooling suggests.
The trend: US cyber agencies are systematically exposing Russian military intelligence tooling and unit structure, turning public disclosure into a weapon that forces GRU operators to constantly re-engineer their access.