Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatstate-sponsored-disruptioncritical-infrastructure-threat

Russian Cyber Operations Hit Ukraine and Expand to Allied Governments

Updated 28d agoFirst seen May 25, 20266 sources

Ukraine has remained a primary target and proving ground for Russian-linked cyber operations, from the Petya/NotPetya outbreak that began via Ukrainian networks and crippled government agencies, banks, transport systems, industrial firms, and Chernobyl monitoring systems, to later destructive malware planted in dozens of Ukrainian government and private-sector networks. Microsoft said the 2022 malware was discovered alongside website defacements affecting Ukrainian entities and appeared designed for later activation, while officials warned such activity could accompany broader military escalation. Earlier attacks on Ukraine’s power grid, election systems, and software supply chain underscored how repeated intrusions against the country have had consequences far beyond its borders.

The campaign has also extended well outside Ukraine through espionage and supply-chain compromises attributed by officials and researchers to Russian state actors. Microsoft reported that hackers aligned with Russia targeted organizations in 42 countries supporting Ukraine, with nearly two-thirds of espionage victims in NATO states and successful intrusions resulting in data theft in at least a quarter of cases. Separately, suspected S.V.R. operators were tied to a broad intrusion set affecting at least 40 organizations, including U.S. government agencies, technology firms, and cybersecurity companies, reinforcing warnings that attacks first seen in Ukraine can evolve into wider operations against allied governments and critical sectors.

Share:
Russian Cyber Operations Hit Ukraine and Expand to Allied Governments
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jun 22, 20224y ago

Microsoft reports Russian espionage targeting 42 Ukraine-supporting countries

On June 22, 2022, Microsoft said state-backed Russian hackers had conducted strategic espionage against organizations in 42 countries supporting Ukraine, with successful intrusions in 29 percent of cases and data theft in at least a quarter of successful compromises. The company said nearly two-thirds of targets were in NATO countries and also reported intensified Russian influence operations after the invasion.

Feb 28, 20224y ago

Microsoft details cyber threat activity during Russia's invasion of Ukraine

On 2022-02-28, Microsoft published analysis of ongoing cyber threat activity in Ukraine, describing destructive and disruptive operations accompanying Russia's invasion and linking observed activity to Russian state-aligned actors. The report marked a public technical update on the wartime cyber campaign beyond the earlier January malware discovery.

Cyber threat activity in Ukraine: analysis and resources
Jan 13, 20224y ago

Microsoft detects destructive malware on Ukrainian networks

On January 13, 2022, Microsoft discovered a highly destructive malware strain staged on dozens of Ukrainian government and private-sector networks, including government, nonprofit, and IT organizations. Microsoft and U.S. officials said the actor had not yet been specifically attributed at that time, though they warned such cyberattacks could accompany broader Russian escalation.

Website defacements hit Ukrainian government agencies

On January 13, 2022, Ukrainian government agencies reported website defacements amid heightened tensions with Russia. The defacements coincided with the discovery of a separate destructive malware operation on Ukrainian networks.

Dec 17, 20206y ago

Suspected Russian SolarWinds espionage campaign expands to at least 40 victims

By December 2020, Microsoft disclosed that suspected Russian hackers had infiltrated at least 40 organizations, including technology firms, government agencies, and think tanks, in a broad espionage campaign. U.S. officials said the Department of Energy and National Nuclear Security Administration were affected, and intelligence agencies reportedly assessed the operation was conducted by Russia's SVR.

Jun 27, 20179y ago

Petya/NotPetya outbreak begins in Ukraine and spreads globally

On June 27, 2017, the Petya outbreak started in Ukraine, disrupting government networks, banks, industrial firms, transportation systems, and radiation-monitoring systems at Chernobyl before spreading to dozens of countries and international companies. Microsoft and ESET said the attack initially targeted Ukrainian accounting software vendor M.E.Doc, which later denied being the origin point.

Russian cyberattacks begin targeting Ukrainian infrastructure

Since 2014, Ukraine has faced repeated cyberattacks against critical infrastructure and government-related systems, including incidents affecting the power grid and election systems. Ukrainian officials publicly suspected Russian involvement, though direct proof was not established in the cited reporting.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.