Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors
🇷🇺 RU

Military Unit 26165

Also known asmilitary_unit_26165

GRU Military Unit 26165 is a unit within Russia's Main Intelligence Directorate of the General Staff (GRU). In the provided reporting, it is linked to a network of compromised small office/home office (SOHO) routers used to facilitate malicious DNS hijacking and espionage operations. The actors exploited known vulnerabilities and stole credentials for thousands of TP-Link routers, then modified router settings to direct requests to GRU-controlled servers and alter DNS settings. The activity targeted victims worldwide who were of intelligence interest to the Russian government, including military, government, and critical infrastructure organizations and individuals. The content states that compromised routers were identified in the United States and globally, including routers owned by individuals in at least 23 U.S. states. No additional aliases or sub-groups are provided in the content beyond military_unit_26165 and GRU Military Unit 26165.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military
  • Utilities

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • RU
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.