Russian activities associated with APT29 and APT28
Activities associated with the Russian Federation were almost certainly (90–100 %)
part of long-standing campaigns also affecting allies. These malicious activities
have tradecraft, motivation and objectives that overlap significantly with APT29
(known as Midnight Blizzard, BlueBravo and Cozy Bear) and APT28 (known as
Forest Blizzard, BlueDelta and Fancy Bear). The first of the above-mentioned actors
is associated with Russia’s foreign intelligence service (SVR) and the second with
Russian military intelligence (GRU).⁴
Increased activity of PRC-related actors
Over the past several years, NÚKIB has also detected increased activity from actors
associated with the People’s Republic of China (PRC), driven by their heightened focus
on European objectives in the context of the war in Ukraine. In 2023, an intrusion into a strategic institution’s network was highly likely (75–85 %) perpetrated by a Chinese-origin attacker. Mustang Panda’s phishing campaign (known as
RedDelta) has directed significant effort against European objectives, including those
in the Czech Republic, at least since the beginning of Russia’s invasion of Ukraine.
North Korean interest in the defence sector
The Czech Republic was targeted by the North Korean group Lazarus (known as
Diamond Sleet or Labyrinth Chollima) in 2023. The group’s objective was to compromise defence companies in the Czech Republic and other NATO/EU countries. The
group is associated with the Reconnaissance General Bureau (RGB).⁵ and their campaign verifies the interest of selected threat actors in specific sectors of the Czech
industry.
Lower activity of Iran
In the context of the escalation of the Israeli-Palestinian conflict, activities by Iranian
actors targeting the technologies of specific producers in the water sector have
been detected. However, the activity of sophisticated actors operating in line with
Tehran’s interests was lower than in the past.
⁴ See, for example: SVR cyber actors adapt tactics for initial cloud access - NCSC.GOV.UK / BlueBravo Adapts
to Target Diplomatic Entities with GraphicalProton Malware | Recorded Future / Office of Public Affairs
| Justice Department Conducts Court-Authorized Disruption of Botnet Controlled by the Russian Federation’s Main Intelligence Directorate of the General Staff (GRU) | United States Department of Justice /
Vojenské zpravodajství | Tiskové zprávy - Vojenské zpravodajství provedlo aktivní zásah v kybernetickém
prostoru (vzcr.cz)
⁵
See, for example: Treasury Sanctions North Korean State-Sponsored Malicious Cyber Groups | U.S.
Department of the Treasury / Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations | Mandiant
23