Cyber Threat Actor: Ivan Sergeyevich Yermakov
| Actor Type | Location | Known Incidents |
Nation State
|
Russia
|
1 incident |
|---|
Profile
Ivan Sergeyevich Yermakov is an alias associated with a threat actor linked to Russian state intelligence activities. The individual is known to operate from Russia and has been identified in public attributions as part of the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). This alias appears in connection with cyber operations that combine espionage with influence efforts. The actor’s known activities are limited to the information provided in the source material, which describes a specific campaign rather than a broader pattern of behavior.
The actor’s targeting has been observed against international anti‑doping organizations and the global sports governing body FIFA, indicating a focus on the sports sector and entities involved in regulating athletic competition. The geographic scope of the targeting is international, reflecting the global nature of the events and organizations involved. Strategic objectives identified in the reported operation include espionage, specifically the theft of confidential medical records, athlete therapeutic use exemptions, and anti‑doping strategies, as well as influence operations designed to discredit investigations into Russia’s state‑sponsored doping program through the dissemination of modified stolen data and fabricated narratives. No financial motive is mentioned in the source material.
Observed tactics, techniques, and procedures include the use of spearphishing messages to gain initial access, close‑access Wi‑Fi compromises conducted during major global sporting events, and the creation of a false hacktivist persona identified as “Fancy Bears’ Hack Team” to leak altered stolen data. Additionally, the actor engaged in direct outreach to journalists to amplify false stories about athlete drug use, thereby leveraging media channels as part of the influence campaign. No specific malware families or custom tooling are referenced in the available information, so the description is limited to these social engineering and access methods.
Attribution to the Russian GRU establishes a clear state nexus, indicating that the actor operates under the direction or support of a governmental intelligence service rather than as an independent criminal group. The most significant publicly reported operation associated with this alias is the 2014 cyber espionage and influence campaign targeting anti‑doping bodies and FIFA, which combined data theft with coordinated disinformation to affect public perception and undermine investigative efforts. This operation exemplifies the actor’s blend of traditional espionage tactics with information warfare objectives.
