Lyce · Hybrid Watch

hw_b827b4934ebfe902

Russian APT28 conducts cyberattacks on Czech government and defence institutions.

Czech authorities jointly with EU and NATO partners publicly tied a campaign of cyber intrusions to the Russian-linked hacking group APT28 (also known as Fancy Bear), affiliated with the GRU. The campaign targeted defence procurement portals, diplomatic email servers and internal administrative networks, employing phishing emails, zero-day vulnerabilities (notably in Microsoft Outlook) and lateral movement inside key systems. The assaults aimed at exfiltrating documents on Czech military cooperation, Ukraine-related logistics and allied intelligence sharing. After detection, the Czech Ministry of Foreign Affairs issued a formal condemnation, noting that the attacker profile matched Russia’s state-sponsored modus operandi. Because the targets were government/defence systems and the operation had strategic consequences, this incident classifies as a significant cyberattack. It underscores Moscow’s use of cyber tools within a hybrid warfare framework to degrade, distort or steal from allied states, not merely to defame or influence.

Occurrence
2024-03-05
Publication
2024-03-04T23:00:00Z
First observed
2026-09-24T06:09:10.079Z
Review status
Not assessed
Countries
CZ
Updated
2026-09-27T23:56:59.668Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-03-04T23:00:00Z

    Czech authorities jointly with EU and NATO partners publicly tied a campaign of cyber intrusions to the Russian-linked hacking group APT28 (also known as Fancy Bear), affiliated with the GRU. The campaign targeted defence procurement portals, diplomatic email servers and internal administrative networks, employing phishing emails, zero-day vulnerabilities (notably in Microsoft Outlook) and lateral movement inside key systems. The assaults aimed at exfiltrating documents on Czech military cooperation, Ukraine-related logistics and allied intelligence sharing. After detection, the Czech Ministry of Foreign Affairs issued a formal condemnation, noting that the attacker profile matched Russia’s state-sponsored modus operandi. Because the targets were government/defence systems and the operation had strategic consequences, this incident classifies as a significant cyberattack. It underscores Moscow’s use of cyber tools within a hybrid warfare framework to degrade, distort or steal from allied states, not merely to defame or influence.