GRU Unit 29155 is a Russian military intelligence threat actor associated with the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). In cyber reporting it has also been tracked as Cadet Blizzard and Ember Bear. The unit has been linked to offensive computer network operations, cyber espionage, disruptive activity, and hybrid operations aligned with Russian state objectives, particularly against Ukraine, EU member states, NATO-aligned countries, and other international targets. The group has been associated with attacks on critical infrastructure and government-related targets, including activity tied to Ukraine and Europe. Public reporting has linked Unit 29155 to the WhisperGate campaign targeting Ukraine, and later reporting assessed that the unit leveraged criminal and quasi-criminal access ecosystems to expand its reach. This includes reported use of SocGholish delivery chains to target victims and overlap with RomCom-related intrusion activity, illustrating a pattern of combining state-directed objectives with tooling, access brokers, or malware distribution channels more commonly seen in cybercrime. Operationally, GRU Unit 29155 has been described as conducting offensive cyber operations against global entities and as collaborating with external hacker networks and cybercriminal facilitators. Reporting has also described recruitment support from Russian-linked intermediaries, including efforts to source hackers and cyber specialists from universities and academies in Russia. Individuals linked to the unit have been identified as facilitating infrastructure, payments, and coordination with outside operators, indicating an ecosystem-based operating model rather than a purely self-contained military unit. Observed tradecraft includes use of compromised legitimate websites and fake software update lures through SocGholish-style infection chains, rapid follow-on payload deployment, PowerShell-based reconnaissance, persistence mechanisms, custom backdoors, and staged loader execution. The unit has also been associated with malware and intrusion sets connected to RomCom operations, suggesting an ability to blend espionage, disruption, and opportunistic access techniques. Its targeting has shown particular interest in organizations with real or perceived links to Ukraine, even when those organizations are located outside the immediate conflict zone. GRU Unit 29155 should be understood as a Russian state-linked actor operating at the intersection of military intelligence, cyber sabotage, espionage, and hybrid influence-supporting operations. Known aliases include Cadet Blizzard and Ember Bear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian military intelligence unit linked to cyber-attacks against critical infrastructure and to the WhisperGate malware campaign targeting Ukrainian critical infrastructure.
Russian GRU unit involved in cyber and hybrid threat operations and recruitment of hackers and cyber specialists via cybercriminal and private-sector intermediaries.
Russian military intelligence cyber/hybrid operations unit sanctioned for directing cyber and hybrid threat operations and collaborating with cybercriminal proxies for recruitment.
GRU Unit 29155 (Cadet Blizzard) is known for conducting hybrid threats, including cyberattacks and sabotage, targeting EU member states, NATO allies, and Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.