GRU is Russia’s military intelligence service, formally known as the Main Intelligence Directorate of the General Staff. It is a state intelligence organization of the Russian Federation and a longstanding actor in cyber espionage, information operations, sabotage, and covert action. In cybersecurity reporting, GRU is widely associated with aggressive operations against governments, political organizations, critical infrastructure, defense-related entities, and foreign states viewed as strategic adversaries of Russia. GRU has been publicly linked by multiple governments and judicial actions to major cyber operations, including the 2016 compromise of U.S. Democratic Party organizations and related hack-and-leak activity. Public indictments and attribution statements identify GRU Units 26165 and 74455 as central to that campaign, using spearphishing, credential theft, malware deployment, persistence mechanisms, data exfiltration, and staged information release through cutouts and personas to influence political outcomes. GRU has also been attributed by the United States and United Kingdom for disruptive distributed denial-of-service activity against Ukrainian government and banking targets in February 2022, reflecting its role in hybrid operations supporting broader Russian military objectives. Beyond direct intrusions, GRU has used compromised network infrastructure and botnets to conceal or relay malicious traffic. U.S. authorities stated that a botnet of compromised Ubiquiti Edge OS routers dismantled in 2024 had been operated by the GRU to proxy traffic used in cyberespionage attacks against the United States and allied nations. This aligns with a broader pattern of exploiting internet-exposed edge devices, leased infrastructure, and intermediary systems to obfuscate attribution and support operational reach. GRU is also associated with non-cyber covert action and hybrid warfare. It has been tied to sabotage and targeted violence in Europe, and the United Kingdom attributed the 2018 Salisbury Novichok poisoning to the Russian state, with GRU identified in public reporting as having targeted the Skripals. More broadly, GRU is assessed as a key instrument of Russian gray-zone activity, combining cyber operations, psychological operations, influence activity, and physical sabotage below the threshold of open armed conflict. The service maintains specialized structures for psychological and information operations in addition to cyber capabilities. Reporting describes regional PSYOP and information-operations units across Russian military districts, as well as GRU-linked formations such as Unit 67606, also known as the 127th Separate Reconnaissance Brigade, in the Southern Military District and Black Sea Fleet. That unit has been described as combining reconnaissance, electronic warfare, unmanned systems, and embedded psychological-operations capabilities, illustrating GRU’s integration of intelligence, electronic attack, and influence functions in operational theaters. Known aliases and naming variants include GRU, Main Intelligence Directorate, and Main Intelligence Directorate of the General Staff. The organization is distinct from Russia’s SVR and FSB, though all three appear in Russian intelligence operations. GRU remains one of the most prominent and operationally aggressive Russian state threat actors in both cyber and hybrid conflict.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NotPetya attacks began by targeting Ukrainian agencies, but it quickly spread through the use of the EternalBlue exploit, which was developed by the National Security Agency and used in the WannaCry ransomware attacks.
In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as conducting targeted violence and industrial sabotage in Europe, including the Salisbury poisoning and a broader Russian-directed arson/sabotage network using criminal proxies recruited via Telegram.
Used the Moobot botnet of compromised Ubiquiti Edge OS routers to proxy malicious traffic in cyberespionage operations.
Russian military intelligence is described as operating a regional psychological operations and information operations structure across military districts, including a unique PSYOP-capable unit, military unit 67606, in the Black Sea Fleet.
Russian military intelligence service identified as a principal espionage and hybrid cyber threat to Switzerland and as using Swiss-based infrastructure for operations abroad.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.