Nations are increasingly integrating cyberspace into their military and national security strategies, developing both defensive and offensive capabilities to project power and protect their interests. Experts highlight that while technological advances in forensics and artificial intelligence have improved cyber defense, attributing responsibility for cyber operations remains a significant challenge. The formal recognition of cyberspace as a domain of warfare by organizations like NATO has led to the establishment of specialized units and procedures for both conducting and attributing cyber activities, often in coordination with other domains of conflict.
Recent conflicts, such as the war in Ukraine, have demonstrated the evolving nature of offensive cyber operations, with countries like Ukraine leveraging both state and non-state actors to conduct attacks that target military and civilian infrastructure. These operations have sometimes challenged established international norms and legal frameworks, as seen in Ukraine's willingness to militarize hacktivist groups and target a broad range of assets to achieve strategic objectives. The adaptation of adversaries and the ongoing debate over responsible behavior in cyberspace underscore the complexity and high stakes of modern cyber conflict.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
A Lawfare analysis published in November 2025 argued that the Russia-Ukraine war demonstrated the strategic effectiveness of sustained offensive cyber tempo and the militarization of non-state actors, challenging Western preferences for legally constrained 'responsible' cyber behavior.
After initially not integrating hacktivists and often relying on purported 'fake hacktivist' personas, Russia later reportedly adopted a model closer to Ukraine's, including battlefield-relevant intrusions attributed to KillNet.
Ukrainian government statistics cited in the reference indicate that since 2022, high-severity Russian cyber incidents against Ukraine have dropped sharply even as the total number of incidents increased.
Russia's full-scale invasion of Ukraine began, creating the wartime context in which both countries' cyber operations and related targeting patterns evolved.
As the conflict progressed, Russia's cyber activity reportedly moved away from the most severe disruptive incidents and toward intelligence gathering and targeting more directly relevant to the war theater.
During the war, Ukraine appears to have targeted a wide range of Russian civilian and government digital assets while partnering with domestic hacktivists and international volunteers, with public acknowledgments and awards from Ukrainian military and intelligence bodies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.