**Targets:** Bellingcat **Notes:** During Ukrainian Revolution
Targeted Countries / Regions
Executive Summary
Cyber Berkut is a nation-state threat actor known for its advanced persistent threat (APT) capabilities primarily engaging in espionage activities. Targeting sectors such as media, government, and defense, particularly in the United Kingdom, Cyber Berkut poses significant risks to sensitive data and national security through sophisticated attack methods.
Goals & Targeting
Cyber Berkut's strategic objectives center on espionage for political and military advantage, targeting sectors likely to hold sensitive information relevant to Russia's interests. The group's focus on the UK suggests a geopolitical rivalry or intelligence-gathering on Western policies affecting Ukraine. Their victims include high-value targets in media, government, and defense sectors where data breaches offer maximum impact.
Enhanced Description
Cyber Berkut is a state-sponsored cyber-espionage group primarily attributed to Russia, known for its involvement during and after the Ukrainian Revolution. The group has targeted media outlets, government agencies, and defense sectors, focusing on extracting sensitive information and conducting surveillance. Cyber Berkut's operations are characterized by long-term campaigns aiming to establish persistent access within targeted networks. Despite their extensive activity, specific details about their tools and techniques remain scarce, making them difficult to attribute definitively. Their primary motivation aligns with broader Russian foreign policy goals, including gathering intelligence and undermining adversarial states.
Key Capabilities
MITRE ATT&CK Tactics
Software / Tooling
Campaigns & Victims
Cyber Berkut is known for sustained campaigns targeting media entities like Bellingcat, aiming to disrupt and gather intelligence. Their activity during the Ukrainian Revolution underscores their long-term operational strategy. The group employs patient tactics, often maintaining access over extended periods to facilitate data exfiltration. While specifics are limited, they demonstrate adaptability in attack vectors and target selection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Cyber Berkut's details is moderate due to limited specific intelligence, primarily from circumstantial evidence. Gaps include exact TTPs, associated tools, and the full scope of their campaigns. More comprehensive reporting would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics