Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-disruptioncritical-infrastructure-threathacktivist-operation

Escalating Russian Hybrid Warfare and Policy Responses in Europe

Updated 3mo agoFirst seen Feb 24, 20263 sources

New analysis warns Russia is likely to escalate its opportunistic hybrid activity in Europe into a more coordinated campaign consistent with New Generation Warfare (NGW) doctrine, integrating cyber operations, influence activity, and sabotage across a broader geographic footprint and at higher tempo. The assessment anticipates more synchronized, multi-domain actions designed to degrade NATO cohesion and readiness—such as pairing physical disruption (for example, airspace violations affecting critical infrastructure like airports) with cyberattacks (for example, DDoS against communications) to amplify operational and psychological impact.

Ukrainian officials are simultaneously pushing for tighter regulation of Telegram, citing its repeated use by Russian intelligence to recruit locals for sabotage and terrorist attacks; the calls followed a deadly incident in Lviv that Ukrainian leadership attributed to Russia and said involved recruitment via Telegram. Separately, polling across major NATO countries indicates strong public support for treating severe hybrid actions—such as cyberattacks that shut down hospitals or power grids and sabotage of undersea cables or energy pipelines—as acts of war, highlighting a growing gap between public sentiment and NATO governments’ typically restrained responses to hybrid aggression.

Share:
Escalating Russian Hybrid Warfare and Policy Responses in Europe
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 24, 20264mo ago

Recorded Future assesses likely escalation of Russian hybrid warfare in Europe

A Recorded Future report published on February 24, 2026 assessed that Russia is likely to escalate over the next two years into a more deliberate Europe-wide hybrid campaign combining cyberattacks, sabotage, influence operations, and infrastructure harassment. The report also outlined mitigations for governments and private-sector critical infrastructure operators.

Ukraine officials call for tighter Telegram regulation

Following the Lviv attack, senior Ukrainian officials and lawmakers pushed for tighter regulation of Telegram and other anonymous platforms. Proposed responses included limiting app functions, banning the service, or requiring compliance with European regulatory standards.

Feb 22, 20264mo ago

Polling shows majorities in five NATO countries view hospital cyberattacks as acts of war

A POLITICO poll in the United States, Canada, France, Germany, and the United Kingdom found majorities in all five countries believe cyberattacks that shut down hospitals or power grids should be treated as acts of war. The poll also found majority support for classifying sabotage of undersea cables or energy pipelines as acts of war.

Attack in Lviv kills police officer and injures 25

An overnight attack in Lviv on February 22 killed a police officer and injured 25 others. President Volodymyr Zelenskyy said Russia organized the attack and that the perpetrators had been recruited via Telegram.

Feb 1, 20242y ago

Ukrainian military intelligence warns Telegram poses security risks

In February 2024, Ukraine’s military intelligence warned that Telegram created security threats. The warning was later cited as an early official concern about the platform’s role in Russian influence and recruitment activity.

Jan 1, 20242y ago

Russian hybrid attacks in NATO states increase after Ukraine invasion

Since the 2022 invasion, Russia has conducted increasingly aggressive but largely opportunistic hybrid warfare in NATO countries, including cyber, sabotage, influence activity, and pressure on critical infrastructure. Analysts say these incidents have become more frequent in recent years, including attacks or sabotage involving undersea cables and energy infrastructure.

Feb 24, 20224y ago

Russia launches full-scale invasion of Ukraine

Russia began its full-scale invasion of Ukraine in February 2022. Subsequent reporting and analysis describe this as the starting point for increasingly aggressive Russian hybrid activity affecting NATO territory.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Organizations
7 linked
Recorded FutureTikTokGazpromMicrosoft CorporationSophosGooglePolitico
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.