Russia
Russia is described in the provided content as a hostile nation-state cyber actor and a source of broader hybrid threats. The reporting attributes to Russia a campaign of cyberattacks, sabotage, disinformation, and provocation across Europe, and characterizes Moscow as operationally aggressive in integrating cyber operations into military campaigns, particularly during the invasion of Ukraine. The content states that Russia uses disruptive attacks, information campaigns, and pre-positioned access during regional conflicts. Targets mentioned in the content include U.S. critical infrastructure, European states and institutions, Danish critical infrastructure and election-related websites, Moldova’s electoral systems and political process, undersea cable infrastructure, transport hubs, logistics hubs, and the U.S. court system. Russia is also repeatedly cited alongside China as a threat to subsea cable infrastructure and as a persistent risk to U.S. critical infrastructure. Specific activity described in the content includes: destructive and disruptive cyberattacks on a Danish water utility in 2024 that caused burst pipes and temporary outages; denial-of-service attacks on Danish websites ahead of regional and local elections; alleged orchestration of a cyberattack on Moldova’s Central Electoral Commission as part of a wider hybrid campaign; DDoS activity using hijacked routers, AI-driven disinformation, troll-network propaganda, vote-buying, and efforts to provoke unrest in Moldova; influence operations and AI-generated propaganda on TikTok targeting Moldovan President Maia Sandu; cyberattacks, sabotage, and disinformation campaigns across Europe; suspected involvement in undersea cable disruption and suspicious cable activity; GPS jamming affecting a flight carrying European Commission President Ursula von der Leyen; and at least partial responsibility, according to cited reporting, for a cyberattack on the U.S. courts’ case management environment in which attackers reportedly spent months searching court records. The content also references Russian operations against Ukraine’s power grid in 2015 and 2016 as an example of cyber-enabled grid disruption requiring months of preparation. NATO and EU-related reporting in the content frames Russian activity as hybrid warfare designed to destabilize, test resolve, degrade coordination, strain logistics, and weaken support for Ukraine while remaining below the threshold of armed response. No distinct sub-groups are identified as aliases for this actor in the provided content, though one mention references a Russian cyber-spy crew called Laundry Bear.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- telecommunications
Tradecraft
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-linked threat actors have a history of targeting critical infrastructure, including successful disruptions of power grids in Ukraine, and are expected to intensify activity against U.S. sectors following geopolitical events.
Engaged in a campaign of sabotage, hacking, and disinformation targeting European infrastructure, including suspected involvement in undersea cable disruptions in the Baltic Sea region since 2022.
Conducting cyber operations aimed at degrading coordination, straining logistics, and testing alliance cohesion, particularly in the context of Ukraine and potential Taiwan contingencies.
Russia integrates cyber operations into military campaigns, using disruptive attacks, information campaigns, and pre-positioned access to support regional conflicts and strategic objectives.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.