Unit 26165 is a cyber operations component of Russia’s Main Directorate of the General Staff (GRU) and is widely tracked as a Russian state threat actor engaged in espionage, information operations support, and disruptive cyber activity. The unit is commonly associated with high-profile GRU intrusion activity and is regarded as part of Russia’s broader military intelligence cyber apparatus. Unit 26165 has been linked to operations targeting the United States, European countries, Ukraine, and other states aligned with Russian strategic interests. Its targeting has historically focused on government, military, diplomatic, political, defense, and other high-value sectors. Reported activity includes credential theft, phishing and other social engineering operations, account compromise, malware-enabled intrusion campaigns, and the use of compromised network infrastructure to proxy malicious traffic and support follow-on operations. The unit has been associated with campaigns that abuse legitimate communications workflows and trusted infrastructure to gain access to victim accounts or systems. Tradecraft attributed to the group includes spearphishing, credential harvesting, use of stolen authentication material, deployment or reuse of malware families aligned with Russian military intelligence objectives, and operational use of botnets or compromised edge devices to conceal origin, relay traffic, and enable targeting against the United States and allied nations. Unit 26165 is a nation-state actor operating on behalf of the Russian government. It is best understood as a GRU military intelligence cyber element rather than a financially motivated criminal group, although its operations may overlap with infrastructure and techniques also seen in broader Russian cyber ecosystems. Public reporting often treats it as one of the principal GRU units responsible for offensive cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Russia-linked operator of a botnet of compromised Ubiquiti Edge OS routers used to proxy malicious traffic.
Referenced as a named Russian threat actor/unit associated with high-end malware campaigns, but no further operational detail is provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.