Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lifting Zmiy

Also known as: Black Owl, Hoody Hyena, APT28, Fancy Bear, has been, Sofacy, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, Pawn Storm, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork, Seedworm, Paper Werewolf, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, BAITSWITCH, SIMPLEFIX

Description

Rostelecom's security team has discovered a new APT group that is breaching companies via industrial PLCs. Named Lifting Zmiy, the group's first attacks were traced back to October 2023. The group targeted PLCs from Russian company Tech-Automatics usually used with elevators and which were still using their default passwords. Rostelecom has linked the group to intrusions at a Russian government contractor, two telecom operators, and an IT company. The company says the group collected and exfiltrated data and then destroyed the victim's infrastructure. Rostelecom says Lifting Zmiy uses Starlink infrastructure for attacks and appears to operate out of Eastern Europe.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Education
Manufacturing
Healthcare
Information technology
Transportation
Pharmaceutical
Maritime
Think tank
Construction
Retail
Critical infrastructure
Utilities
Chemical
Nuclear
Entertainment
Hospitality
Mining
Gaming
Legal services
Aviation
Oil gas
Food agriculture

Targeted Countries / Regions

US
CN
RU
GB
IN
KR
JP
DE
IR
TW
CA
SA
FR
IL
TR
AU
PK
KZ
UA
ES
VN
BR
PL
SG
NL
AE
IT
BY
IQ
MX
RO
SY
AZ
EG
LB

AI Analysis

· 1 week ago

Executive Summary

Lifting Zmiy is a recently identified Advanced Persistent Threat (APT) group targeting industrial control systems in Russia. The group exploits vulnerabilities in programmable logic controllers (PLCs) using default credentials and has been linked to attacks on critical infrastructure sectors, including government contractors, telecom operators, and IT companies.

Goals & Targeting

Lifting Zmiy's strategic objectives appear to focus on compromising critical industrial and government infrastructure within Russia. The targeting of PLCs suggests their interest in disrupting or controlling physical processes, potentially leading to significant operational disruptions. Their selection of Starlink infrastructure indicates an effort to circumvent traditional monitoring tools and maintain operational security.

Enhanced Description

Lifting Zmiy was discovered by Rostelecom's security team in October 2023. The group exploits industrial PLCs from Tech-Automatics, which are commonly used in elevator systems and other industrial applications. These devices often operate with default passwords, making them easy targets for initial compromise. Lifting Zmiy has targeted several high-profile victims, including a Russian government contractor, two telecom operators, and an IT company. The group's tactics involve data collection, exfiltration, and infrastructure destruction. Notably, the actors utilize Starlink satellite internet to facilitate their attacks, suggesting they operate from Eastern Europe. This unique combination of attack vectors and infrastructure usage indicates a high level of sophistication for a relatively new threat actor.

Key Capabilities

  • Exploitation of industrial control systems (ICS)
  • Use of default credentials for initial access
  • Data exfiltration and destruction activities
  • Sophisticated use of satellite-based communication
  • Targeting critical infrastructure sectors

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection

ATT&CK Techniques

T1059.003 - spear-phishing with附件
T1078 - credential dumping
T1566 - impact processes and binaries
T1040 - web shell creation

Software / Tooling

Custom PLC exploitation tools
Starlink satellite communication
Undetected or custom malware for ICS targeting

Campaigns & Victims

Lifting Zmiy has displayed a campaign pattern focused on stealth and precision. The group targets specific sectors with highvalue assets, utilizing their knowledge of industrial systems to maximize impact. While their operational tempo is relatively new, the group demonstrates a rapid development cycle, quickly adapting to exploit identified vulnerabilities. Notable past operations include multiple intrusions into Russian government contractors and telecom operators, leading to data breaches and infrastructure destruction.

IOC Patterns

  • Use of default credentials on industrial devices
  • PLC configuration changes or unauthorized access
  • Malicious activity over Starlink satellite channels
  • Spear-phishing campaigns targeting industrial employees

Recommended Actions

  • Implement multi-factor authentication (MFA) for industrial systems.
  • Monitor network traffic for unusual patterns on Starlink connections.
  • Conduct regular vulnerability assessments of ICS devices.
  • Educate staff about phishing attempts and suspicious emails.
  • Segment industrial networks from general IT infrastructure to contain breaches.

Suggested Tags

APT
Espionage
Industrial Espionage
Sectors: Critical Infrastructure
Geopolitical: Eastern Europe

Confidence Assessment

High confidence in the identification of Lifting Zmiy as a new APT group targeting industrial systems. However, specific technical details regarding their tools and attack vectors remain limited, which introduces some uncertainty about their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. thehackernews.com — Cited by web research for: BAITSWITCH
  4. www.rescana.com — Cited by web research for: captchanom.top
  5. chintangurjar.com — Cited by web research for: Gaming

Intel Summary

0

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
Espionage
Industrial Espionage
Sectors: Critical Infrastructure
Geopolitical: Eastern Europe

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.