GRU is the Russian Federation’s military intelligence service, formally known as the Main Intelligence Directorate of the General Staff. It is a state intelligence organization and a longstanding source of cyber espionage, information operations, and disruptive cyber activity attributed by multiple governments and judicial actions. In cybersecurity reporting, GRU is widely associated with operations conducted by specialized units including Unit 26165 and Unit 74455, which were indicted by the United States for the 2016 compromise of Democratic Party organizations and related hack-and-leak activity. GRU has also been publicly linked to disruptive operations against Ukraine, including the February 2022 distributed denial-of-service attacks targeting Ukrainian government and banking entities. GRU cyber operations have targeted governments, political parties, election-related infrastructure, defense organizations, critical infrastructure, logistics entities, technology companies, and research institutions. Reported targeting has included the Democratic National Committee, the Democratic Congressional Campaign Committee, the Clinton campaign, Ukrainian state and financial institutions, and Western organizations of strategic intelligence value. Switzerland has identified Russia, including the GRU, as a principal espionage threat, reflecting the service’s broader role in intelligence collection against foreign governments, academia, telecommunications providers, and service providers. Observed tradecraft attributed to GRU includes spearphishing and credential theft, malware deployment, persistence on victim networks, keystroke logging and screenshot capture, data exfiltration, use of false online personas for information laundering, and timed release of stolen material to maximize political effect. Public reporting and indictments have tied GRU operations to personas and fronts such as Guccifer 2.0 and DCLeaks in support of influence operations. GRU has also been associated with the use of compromised edge devices and botnets for operational obfuscation and traffic proxying, including the Moobot botnet of compromised Ubiquiti Edge OS routers dismantled in 2024. Beyond network intrusions, GRU is associated with broader hybrid and psychological operations capabilities. Reporting describes regional psychological operations and information operations structures across Russian military districts, as well as specialized formations such as Unit 67606, also known as the 127th Separate Reconnaissance Brigade, assessed to support Black Sea Fleet and Southern Military District missions with embedded psychological operations capabilities alongside reconnaissance, electronic reconnaissance, and unmanned systems. GRU is commonly referenced simply as GRU, though formal and translated names include Main Intelligence Directorate and Main Directorate of the General Staff. It is distinct from Russia’s SVR and FSB, but often discussed alongside them as one of the Russian state services most active in foreign espionage, cyber operations, and influence campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NotPetya attacks began by targeting Ukrainian agencies, but it quickly spread through the use of the EternalBlue exploit, which was developed by the National Security Agency and used in the WannaCry ransomware attacks.
In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used the Moobot botnet of compromised Ubiquiti Edge OS routers to proxy malicious traffic in cyberespionage operations.
Russian military intelligence is described as operating a regional psychological operations and information operations structure across military districts, including a unique PSYOP-capable unit, military unit 67606, in the Black Sea Fleet.
Russian military intelligence service identified as a principal espionage and hybrid cyber threat to Switzerland and as using Swiss-based infrastructure for operations abroad.
Previously operated a botnet of compromised Ubiquiti Edge OS routers for relay/proxy infrastructure and persistent access. Mentioned as historical targeting of Ubiquiti devices, not as a confirmed exploiter of CVE-2026-47367 specifically.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.