Fancy Bear
16
MENTIONS
10
EPISODES
8
PODCASTS
Search complete. 16 mentions across 10 episodes found for "Fancy Bear".
Sep 18, 2026
'We need to take this seriously' | Burnham leaves UK at risk as NATO allies warn of Russian attacks
A
11:00Andrew NeilHOST
GCHQ and NCSC, that's the main agencies in Britain that try to deal with these cyber attacks, they've identified sustained GRU and FSB activity.
A
11:21Andrew NeilHOST
Take GR Unit 26165, also goes by the name Fancy Bear.
A
11:27Andrew NeilHOST
The UK has attributed to it in 2025-26 widespread hacking of email credentials, compromising routers for DNS hijacking, rerouting traffic through Russian-controlled servers to steal logins, including government and law enforcement accounts.
A
11:50Andrew NeilHOST
Western reporting puts the victim pool, those who've suffered from this, in the tens of thousands across many countries, including the United Kingdom.
27 Second Breaches and Hyperwar
S
6:18speaker_3HOST
Oh, absolutely.
C
6:18Chat GPTHOST
Groups like Russia's Fancy Bear and North Korea's famous Chelima They're using AI to automate their reconnaissance at an unprecedented scale.
S
6:27speaker_3HOST
And North Korea has also been highly successful at scaling insider operations using AI-generated personas.
C
6:33Chat GPTHOST
Oh yeah, the fake remote workers.
27 Second Breaches and Hyperwar
S
5:01speaker_1HOST
too.
C
5:02Chat GPTHOST
Groups like Russia's Fancy Bear and North Korea's famous Cholima, they're using AI to automate their reconnaissance at an unprecedented scale.
S
5:11speaker_1HOST
And North Korea has also been highly successful at scaling insider operations using AI generated personas.
C
5:16Chat GPTHOST
Oh, yeah.
What's hitting Macs so far in 2026, plus OBTS v9 preview (Part 2)
K
14:52Kseniia YamburhGUEST
Lately you, like, saw the techniques, like all, all technique overlaps, yes.
K
14:59Kseniia YamburhGUEST
And, uh, you could say for sure, yeah, like it's, it's, uh, Lazarus or Blue Noroff, or I don't know, Fancy Bear, whatever.
K
15:07Kseniia YamburhGUEST
But now techniques are in public record and, and, uh, criminals, they read, rebuild, and sometimes even improve them beyond the original.
K
15:17Kseniia YamburhGUEST
And with the Digit Stealer, uh, it, it, it's what happened to Digit Stealer because they adopted some, uh, techniques, and they even im- improved them.
The Speed of Threat
R
9:24Robby PereltaHOST
That's what you were defending against, right? Defending
J
9:27Jeff SchiemannGUEST
against APT 28 and 38 North Korean nation-state attackers who were focused on monetizing their attack chain very quickly.
J
9:39Jeff SchiemannGUEST
which to some extent until February this year was pretty much the MO, pretty much the campaign from data extortion to ransom to monetization, crypto theft.
J
9:48Jeff SchiemannGUEST
But we saw the striker hack, right? The striker hack was 100,000 deleted devices using Intune with no ransom.
Cyber Daily News for September 3rd, 2026
S
0:09speaker_0HOST
More than 2,000 leaked documents from Bauman Moscow State Technical University expose a secret department number four that trained hackers and propagandists for the Russian military.
S
0:19speaker_0HOST
The files reveal a program linked to the GRU and advanced groups like APT28 and Sandworm, showing how engineering students are turned into cyber operators.
S
0:28speaker_0HOST
This discovery exposes the deep integration between academic institutions and state-sponsored cyber warfare units.
S
0:36speaker_0HOST
OpenAI has confirmed that its Astra model has reached the highest cybersecurity risk level in its preparedness framework.
CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]
M
3:21Maria VarmazisHOST
[laughs]
D
3:21Dave BittnerGUEST
Fancy Bear, Cozy Bear.
D
3:24Dave BittnerGUEST
Uh, right?
M
3:25Maria VarmazisHOST
Yeah.
D
4:30Dave BittnerGUEST
I guess what I wonder is how much of this is marketing, right? 'Cause when we go to the RSA Conference or, you know, and we see vendors who have big, giant superhero-looking statues of the APTs, it becomes a way to help market your defenses against them.
D
4:55Dave BittnerGUEST
The adversary isn't a big blurry, fuzzy blob on the other side of the world.
D
5:00Dave BittnerGUEST
No, that's Fancy Bear.
D
5:02Dave BittnerGUEST
No, that's, you know, uh, so now we have the Blizzards and the, you know, all, the...
The blacklist boomerang.
M
14:57Maria VarmazisHOST
[laughs]
D
14:57Dave BittnerHOST
Fancy Bear.
D
14:58Dave BittnerHOST
[laughs] Cozy Bear.
D
15:00Dave BittnerHOST
Uh, right?
D
16:06Dave BittnerHOST
I guess what I wonder is how much of this is marketing, right? 'Cause when we go to the RSA Conference or, you know, and we see vendors who have big, giant superhero-looking statues of the APTs, it becomes a way to help market your defenses against them.
D
16:30Dave BittnerHOST
The adversary isn't a big, blurry, fuzzy blob on the other side of the world.
D
16:36Dave BittnerHOST
No, that's Fancy Bear.
D
16:38Dave BittnerHOST
No, that's, you know...
Risky Bulletin: Two TeamPCP members arrested in Australia
C
6:07Claire AirdHOST
The FBI seized a version of the botnet in twenty twenty-four.
C
6:11Claire AirdHOST
That was being used by APT28, a cyber unit inside Russia's military intelligence agency.
C
6:18Claire AirdHOST
Social media giant Meta has disrupted the operations of six spyware and surveillance-for-hire vendors active on its platforms.
C
6:27Claire AirdHOST
Meta says it took down a network of Facebook and Instagram accounts created by Israeli surveillance-for-hire vendor BindSe.
P
Unknown podcast
August 28, 2026 - Cyber Briefing
Aug 28 · 1 Mention
S
1:29speaker_0HOST
Russian APT Blue Delta uses hook edge against European government.
S
1:34speaker_0HOST
Russian state-sponsored group Blue Delta, also known as APT28, conducted an espionage campaign from September 2025 through April 2026, targeting government and diplomatic organizations in Romania, Spain, and Turkey, using a batch script backdoor called hook edge.
S
1:53speaker_0HOST
The malware used webhook.site as command and control infrastructure, and Microsoft Edge to disguise malicious traffic as normal web browsing, delivered through macro-enabled Word documents with diplomatic-themed lures.
S
2:06speaker_0HOST
Organizations should block macros and documents from the internet, monitor scheduled tasks launching scripts from user-writable folders, and flag Microsoft Edge running in headless mode or connecting to webhook services.