Military Unit 26165
GRU Military Unit 26165 is a unit within Russia's Main Intelligence Directorate of the General Staff (GRU). In the provided reporting, it is linked to a network of compromised small office/home office (SOHO) routers used to facilitate malicious DNS hijacking and espionage operations. The actors exploited known vulnerabilities and stole credentials for thousands of TP-Link routers, then modified router settings to direct requests to GRU-controlled servers and alter DNS settings. The activity targeted victims worldwide who were of intelligence interest to the Russian government, including military, government, and critical infrastructure organizations and individuals. The content states that compromised routers were identified in the United States and globally, including routers owned by individuals in at least 23 U.S. states. No additional aliases or sub-groups are provided in the content beyond military_unit_26165 and GRU Military Unit 26165.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Utilities
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- RU
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.