Also known as: Black Owl, Hoody Hyena, APT28, Fancy Bear, has been, Sofacy, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, Pawn Storm, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Seedworm, Paper Werewolf, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, BAITSWITCH, SIMPLEFIX
Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were traced back to October 2023. The group targeted PLCs from Russian company Tech-Automatics usually used with elevators and which were still using their default passwords. Rostelecom has linked the group to intrusions at a Russian government contractor, two telecom operators, and an IT company. The company says the group collected and exfiltrated data and then destroyed the victim's infrastructure. Rostelecom says Lifting Zmiy uses Starlink infrastructure for attacks and appears to operate out of Eastern Europe.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lifting Zmiy is a recently identified Advanced Persistent Threat (APT) group targeting industrial control systems in Russia. The group exploits vulnerabilities in programmable logic controllers (PLCs) using default credentials and has been linked to attacks on critical infrastructure sectors, including government contractors, telecom operators, and IT companies.
Goals & Targeting
Lifting Zmiy's strategic objectives appear to focus on compromising critical industrial and government infrastructure within Russia. The targeting of PLCs suggests their interest in disrupting or controlling physical processes, potentially leading to significant operational disruptions. Their selection of Starlink infrastructure indicates an effort to circumvent traditional monitoring tools and maintain operational security.
Enhanced Description
Lifting Zmiy was discovered by Rostelecom's security team in October 2023. The group exploits industrial PLCs from Tech-Automatics, which are commonly used in elevator systems and other industrial applications. These devices often operate with default passwords, making them easy targets for initial compromise. Lifting Zmiy has targeted several high-profile victims, including a Russian government contractor, two telecom operators, and an IT company. The group's tactics involve data collection, exfiltration, and infrastructure destruction. Notably, the actors utilize Starlink satellite internet to facilitate their attacks, suggesting they operate from Eastern Europe. This unique combination of attack vectors and infrastructure usage indicates a high level of sophistication for a relatively new threat actor.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Lifting Zmiy has displayed a campaign pattern focused on stealth and precision. The group targets specific sectors with highvalue assets, utilizing their knowledge of industrial systems to maximize impact. While their operational tempo is relatively new, the group demonstrates a rapid development cycle, quickly adapting to exploit identified vulnerabilities. Notable past operations include multiple intrusions into Russian government contractors and telecom operators, leading to data breaches and infrastructure destruction.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of Lifting Zmiy as a new APT group targeting industrial systems. However, specific technical details regarding their tools and attack vectors remain limited, which introduces some uncertainty about their full capabilities.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
0
Tactics