Cyber Threat Actor: FSB
| Actor Type | Location | Known Incidents |
Nation State
|
Russia
|
2 incidents |
|---|
Profile
The threat actor known as the FSB, also referred to as the Federal Security Service, is the principal security agency of the Russian Federation. Public attributions link it to state‑directed cyber operations conducted on behalf of the Russian government. Its activities are carried out under the authority of the Russian state, and it is not described as a criminal consortium in the available reporting. The alias FSB appears in open‑source reports that connect the agency to specific intrusion campaigns.
Observed targeting includes the energy sector, specifically business networks of a U.S. nuclear operator and related energy firms. Additionally, the actor has been linked to a cyber‑espionage network operating in the Czech Republic that involved Russian nationals holding local citizenship. Strategic objectives identified in the reporting are espionage and reconnaissance intended to establish footholds for possible future disruptive actions. No financial motive is mentioned in the cited incidents.
The reported tactics involve spearphishing emails that masquerade as job applicant résumés. Compromised websites are also used to harvest credentials from targets. In the Czech case, the operation relied on individuals with local citizenship who received funding through the Moscow embassy in Prague. No specific malware families or custom tooling are detailed in the provided sources.
A representative example is the 2017 intrusion into U.S. nuclear and energy company business networks, where attackers gathered credentials from administrative systems without affecting operational controls. Another example is the 2018 dismantling by Czech authorities of a Russian‑linked cyber‑espionage network that operated via locally based Russian nationals and embassy‑funded support. These incidents illustrate the actor’s focus on gathering intelligence and preparing potential access for later actions. The reporting notes that U.S. authorities assessed the 2017 campaign as reconnaissance, while Czech officials described the 2018 network as an espionage effort.
