Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cyber Berkut

Description

**Targets:** Bellingcat **Notes:** During Ukrainian Revolution

Goals & Targeting

Targeted Countries / Regions

GB

AI Analysis

· 1 week ago

Executive Summary

Cyber Berkut is a nation-state threat actor known for its advanced persistent threat (APT) capabilities primarily engaging in espionage activities. Targeting sectors such as media, government, and defense, particularly in the United Kingdom, Cyber Berkut poses significant risks to sensitive data and national security through sophisticated attack methods.

Goals & Targeting

Cyber Berkut's strategic objectives center on espionage for political and military advantage, targeting sectors likely to hold sensitive information relevant to Russia's interests. The group's focus on the UK suggests a geopolitical rivalry or intelligence-gathering on Western policies affecting Ukraine. Their victims include high-value targets in media, government, and defense sectors where data breaches offer maximum impact.

Enhanced Description

Cyber Berkut is a state-sponsored cyber-espionage group primarily attributed to Russia, known for its involvement during and after the Ukrainian Revolution. The group has targeted media outlets, government agencies, and defense sectors, focusing on extracting sensitive information and conducting surveillance. Cyber Berkut's operations are characterized by long-term campaigns aiming to establish persistent access within targeted networks. Despite their extensive activity, specific details about their tools and techniques remain scarce, making them difficult to attribute definitively. Their primary motivation aligns with broader Russian foreign policy goals, including gathering intelligence and undermining adversarial states.

Key Capabilities

  • Advanced persistent threat (APT) campaigns
  • Spear-phishing attacks
  • Zero-day exploits
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Espionage
Collection Activities

Software / Tooling

Custom malware frameworks
Spear-phishing tools
Lateral movement tools

Campaigns & Victims

Cyber Berkut is known for sustained campaigns targeting media entities like Bellingcat, aiming to disrupt and gather intelligence. Their activity during the Ukrainian Revolution underscores their long-term operational strategy. The group employs patient tactics, often maintaining access over extended periods to facilitate data exfiltration. While specifics are limited, they demonstrate adaptability in attack vectors and target selection.

IOC Patterns

  • Spear-phishing emails with geopolitical themes
  • C2 communications via encrypted channels
  • Signs of lateral movement within networks

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts
  • Monitor network traffic for signs of APT activities and data exfiltration
  • Conduct regular vulnerability assessments and patch management
  • Train employees to recognize geopolitical-themed phishing attacks

Suggested Tags

Nation-state
Espionage
Cyber-espionage
Advanced Persistent Threat (APT)
Media sector

Confidence Assessment

Confidence in Cyber Berkut's details is moderate due to limited specific intelligence, primarily from circumstantial evidence. Gaps include exact TTPs, associated tools, and the full scope of their campaigns. More comprehensive reporting would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state
Espionage
Cyber-espionage
Advanced Persistent Threat (APT)
Media sector

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.