Skip to main content
Mallory
1 malware family

Russia

Also known asrussia

Russia is described in the provided content as a hostile nation-state cyber actor and a source of broader hybrid threats. The reporting attributes to Russia a campaign of cyberattacks, sabotage, disinformation, and provocation across Europe, and characterizes Moscow as operationally aggressive in integrating cyber operations into military campaigns, particularly during the invasion of Ukraine. The content states that Russia uses disruptive attacks, information campaigns, and pre-positioned access during regional conflicts. Targets mentioned in the content include U.S. critical infrastructure, European states and institutions, Danish critical infrastructure and election-related websites, Moldova’s electoral systems and political process, undersea cable infrastructure, transport hubs, logistics hubs, and the U.S. court system. Russia is also repeatedly cited alongside China as a threat to subsea cable infrastructure and as a persistent risk to U.S. critical infrastructure. Specific activity described in the content includes: destructive and disruptive cyberattacks on a Danish water utility in 2024 that caused burst pipes and temporary outages; denial-of-service attacks on Danish websites ahead of regional and local elections; alleged orchestration of a cyberattack on Moldova’s Central Electoral Commission as part of a wider hybrid campaign; DDoS activity using hijacked routers, AI-driven disinformation, troll-network propaganda, vote-buying, and efforts to provoke unrest in Moldova; influence operations and AI-generated propaganda on TikTok targeting Moldovan President Maia Sandu; cyberattacks, sabotage, and disinformation campaigns across Europe; suspected involvement in undersea cable disruption and suspicious cable activity; GPS jamming affecting a flight carrying European Commission President Ursula von der Leyen; and at least partial responsibility, according to cited reporting, for a cyberattack on the U.S. courts’ case management environment in which attackers reportedly spent months searching court records. The content also references Russian operations against Ukraine’s power grid in 2015 and 2016 as an example of cyber-enabled grid disruption requiring months of preparation. NATO and EU-related reporting in the content frames Russian activity as hybrid warfare designed to destabilize, test resolve, degrade coordination, strain logistics, and weaken support for Ukraine while remaining below the threshold of armed response. No distinct sub-groups are identified as aliases for this actor in the provided content, though one mention references a Russian cyber-spy crew called Laundry Bear.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • telecommunications
MITRE ATT&CK

Tradecraft

44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

15 of 15 tactics52 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
5 techniques
T1590×4
Gather Victim Network Information
T1591
Gather Victim Org Information
T1592×2
Gather Victim Host Information
T1595×8
Active Scanning
T1598
Phishing for Information
TA0042
Resource Development
4 techniques
T1583×3
Acquire Infrastructure
T1583.001
Domains
T1585×5
Establish Accounts
T1585.001
Social Media Accounts
T1587
Develop Capabilities
T1587.001
Malware
T1588
Obtain Capabilities
T1588.005
Exploits
TA0001
Initial Access
5 techniques
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1190×2
Exploit Public-Facing Application
T1195×8
Supply Chain Compromise
T1195.001
Compromise Software Dependencies and Development Tools
T1195.002×2
Compromise Software Supply Chain
T1199×2
Trusted Relationship
T1566×6
Phishing
TA0002
Execution
1 technique
T1203×3
Exploitation for Client Execution
TA0003
Persistence
2 techniques
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1205
Traffic Signaling
TA0004
Privilege Escalation
1 technique
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
TA0005
Stealth
5 techniques
T1006
Direct Volume Access
T1036
Masquerading
T1078×3
Valid Accounts
T1078.004
Cloud Accounts
T1205
Traffic Signaling
T1218
System Binary Proxy Execution
TA0112
Defense Impairment
1 technique
T1600
Weaken Encryption
TA0006
Credential Access
1 technique
T1040×2
Network Sniffing
TA0007
Discovery
2 techniques
T1040×2
Network Sniffing
T1654×4
Log Enumeration
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
2 techniques
T1119×2
Automated Collection
T1213
Data from Information Repositories
TA0011
Command and Control
2 techniques
T1105
Ingress Tool Transfer
T1205
Traffic Signaling
TA0010
Exfiltration
4 techniques
T1041×2
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1537
Transfer Data to Cloud Account
T1567
Exfiltration Over Web Service
TA0040
Impact
6 techniques
T1485×8
Data Destruction
T1486
Data Encrypted for Impact
T1498×3
Network Denial of Service
T1499
Endpoint Denial of Service
T1565×2
Data Manipulation
T1657
Financial Theft
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping44

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Russia | Mallory