Germany declared a Russian Embassy staff member persona non grata and summoned Russia’s ambassador, saying it would not tolerate espionage—particularly under diplomatic cover—amid heightened tensions tied to Russia’s war in Ukraine. Reporting identified the expelled official as Andrei Mayorov, Russia’s deputy military attaché in Germany, alleged to be a GRU officer and the handler for a dual Ukrainian-German citizen arrested in Berlin on suspicion of spying for Russia.
German prosecutors allege the arrested woman (identified in reporting as Ilona Kopylova/Ilona W.) leveraged contacts with current and former German defence ministry employees to collect information related to German military aid to Ukraine, drone testing sites, and the arms industry, and also helped her handler operate under a false identity to attend political events and cultivate contacts. Russia’s embassy rejected the allegations as a provocation and warned Berlin’s actions would not go unanswered, while German officials framed the expulsion as a clear signal that hostile intelligence activity in Germany will carry consequences.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
After the expulsion, the Russian Embassy in Berlin denied the spying allegations and warned that Moscow would respond. The exchange further escalated tensions between Germany and Russia.
Germany declared a Russian diplomat persona non grata and ordered him to leave immediately over alleged espionage tied to the Ukraine war. Media reports identified him as Andrei Mayorov, Russia’s deputy military attaché in Germany, who was accused of acting as Kopylova’s handler.
German authorities arrested Ilona Kopylova in Berlin on suspicion of espionage for Russia. Prosecutors allege she used contacts linked to Germany’s defense ministry to gather information on military aid to Ukraine, drone testing sites, and the arms industry, and helped her handler attend political events under a false identity.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.