Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatstate-sponsored-disruptionthreat-infrastructure-tracking

US and Allies Expose GRU Hackers Behind Election, NotPetya, and OPCW Operations

Updated 7d agoFirst seen May 25, 20263 sources

US prosecutors and allied governments publicly identified Russian military intelligence officers from the GRU for a series of high-profile cyber operations, linking the same apparatus to election interference, destructive malware, and espionage campaigns. A Mueller indictment detailed how GRU operators allegedly hacked Democratic Party networks, stole documents, and staged their release through online personas and infrastructure designed to obscure Russian involvement. Separately, the US Justice Department charged additional GRU officers over attacks tied to Ukraine, including the NotPetya malware outbreak and intrusions associated with power grid disruptions, underscoring the unit’s role in both covert influence operations and disruptive cyberattacks.

European authorities also exposed a failed close-access GRU operation against the Organisation for the Prohibition of Chemical Weapons (OPCW) in The Hague. Dutch officials said four Russian operatives arrived with Wi‑Fi interception equipment, cash, phones, and receipts that connected them to GRU facilities in Moscow, and later expelled them after reportedly receiving a British intelligence tip. Investigators and media reports tied members of that team to broader targeting of the Skripal investigation, MH17 investigators, and the World Anti-Doping Agency, reinforcing a picture of a global GRU campaign marked by aggressive targeting and, in some cases, operational mistakes that helped attribute the activity.

Share:
US and Allies Expose GRU Hackers Behind Election, NotPetya, and OPCW Operations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 19, 20206y ago

U.S. charges Russian hackers over Ukraine attacks and NotPetya

The U.S. Justice Department announced charges against Russian hackers accused of cyberattacks including Ukraine power grid disruptions and the NotPetya malware attack. The case publicly tied named Russian operatives to some of the most damaging GRU-linked cyber operations.

Oct 4, 20188y ago

Netherlands publicly exposes failed GRU cyberattack on OPCW

Dutch authorities publicly disclosed the previously disrupted 2018 GRU operation against the OPCW, identifying the four operatives and describing the seized hacking gear and evidence. The disclosure highlighted the GRU's interest in chemical weapons and related international investigations.

Jul 18, 20188y ago

Mueller indictment details Russian hacking tied to U.S. election interference

Special counsel Robert Mueller's indictment publicly revealed details about Russian intelligence tradecraft and hacking operations connected to interference in the 2016 U.S. election. The filing added new public attribution and operational detail about the GRU's cyber activities.

Apr 13, 20188y ago

Dutch authorities disrupt OPCW hack attempt and expel four Russian operatives

Dutch authorities, reportedly tipped off by British intelligence, surveilled the GRU team targeting the OPCW, seized their equipment and other materials, and expelled them from the Netherlands. The operation was later linked to broader GRU activity involving the Skripal investigation, MH17 investigators, and WADA.

Apr 10, 20188y ago

GRU officers conduct close-access hacking operation against OPCW in The Hague

In 2018, four Russian GRU operatives traveled to the Netherlands and allegedly prepared a Wi‑Fi hacking operation from near the OPCW headquarters in The Hague. The team arrived via Schiphol airport, rented a car, and carried hacking equipment, cash, phones, and receipts linked to GRU facilities in Moscow.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.