GRU Unit 29155 is a Russian military intelligence unit associated with sabotage, clandestine operations, and destructive cyber activity. Its cyber component is tracked as Cadet Blizzard and Ember Bear. Western governments have linked the unit to cyber operations against Ukraine, NATO countries, and European critical infrastructure, including the WhisperGate campaign against Ukrainian targets. The unit has also been associated with Russian hybrid operations and with recruiting cyber specialists through relationships with external cybercriminal actors and Russian educational institutions. Public reporting has linked Unit 29155 activity to use of SocGholish as an initial-access mechanism and RomCom tooling against organizations with Ukrainian affiliations. Andrey Averyanov is a senior GRU officer who previously commanded the unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unité GRU russe associée à des opérations de sabotage et destructrices, dont des opérations cyber visant l’Ukraine et des pays de l’OTAN.
Russian military intelligence unit linked to cyberattacks, sabotage, and covert operations; its cyber division has been accused of targeting governments, defense organizations, think tanks, and other entities in Ukraine and NATO countries.
Russian military intelligence unit linked to cyber-attacks against critical infrastructure and to the WhisperGate malware campaign targeting Ukrainian critical infrastructure.
Russian GRU unit involved in cyber and hybrid threat operations and recruitment of hackers and cyber specialists via cybercriminal and private-sector intermediaries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.