The Russian Foreign Intelligence Service (SVR) is Russia’s civilian foreign intelligence service and has been publicly attributed as the state actor behind major cyber espionage operations against the United States and allied networks. It is widely associated with long-term, stealthy intrusion activity focused on intelligence collection, strategic access, and compromise of high-value government and enterprise environments. The SVR is notably linked to the 2020 SolarWinds supply-chain compromise, in which malicious code was inserted into the Orion software build environment and distributed through trusted software updates to downstream victims. That operation enabled remote access into selected customer environments and affected prominent U.S. government entities and other organizations. Public reporting also ties the SVR to exploitation of multiple publicly known vulnerabilities against U.S. and allied networks, including exploitation of CVE-2023-42793. Operationally, the SVR has demonstrated strong initial-access tradecraft through exploitation of internet-exposed vulnerabilities and supply-chain compromise, followed by disciplined post-exploitation in victim environments. Its activity is consistent with reconnaissance, persistence, privilege escalation, lateral movement, credential theft, data exfiltration, and defense evasion in support of clandestine intelligence objectives. The actor’s campaigns are characteristic of a nation-state espionage service rather than financially motivated or disruptive criminal operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior threat actor that exploited an earlier TeamCity vulnerability, illustrating historical risk to exposed TeamCity infrastructure.
The Russian Foreign Intelligence Service (SVR) is known for conducting sophisticated cyber espionage campaigns, including the 2020 SolarWinds supply chain attack that compromised numerous organizations globally by infiltrating SolarWinds' software update process.
Attributed sponsor/operator behind the SolarWinds Orion supply-chain compromise, inserting tainted code into SolarWinds’ build environment to gain remote access to downstream customer networks (including US government agencies).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.