Ukrainian hacktivists linked to the Fenix cyber analytics center, supported by InformNapalm, reported compromising accounts belonging to dozens of Russian military personnel and gaining access to monitoring systems used by Russian attack-drone operators. The operation allegedly enabled covert, near real-time surveillance of drone-operator activity and the transfer of collected data to Ukrainian Defense Forces, and it was cited in reporting around Ukraine’s decision to sanction Belarusian leader Alyaksandr Lukashenka over Belarus’s role in enabling Russia’s use of repeater infrastructure on Belarusian territory to extend UAV control and expand strike reach into northern Ukraine, including against energy and rail targets.
Separately, Dutch intelligence services (AIVD/MIVD) warned that Russia is intensifying a broader hybrid warfare campaign across Europe—combining cyberattacks, sabotage, disinformation, covert influence, and espionage—to undermine public trust and weaken support for Ukraine while staying below the threshold of open war. In parallel, telecom-focused research highlighted how public mobile networks are increasingly being used as command/telemetry links for combat drones, citing examples from the Russia–Ukraine war and describing how 4G/5G standards work (e.g., 3GPP enhancements in Releases 15–18) has made cellular-connected UAV operations more feasible—raising infrastructure-security concerns for mobile operators and national critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On February 18, 2026, Ukrainian President Volodymyr Zelenskyy imposed sanctions on Belarusian leader Alyaksandr Lukashenka, citing Belarus's role in enabling Russia's war effort, including support for attack UAV operations.
During the cyber operation disclosed in 2026, Ukrainian hacktivists allegedly maintained round-the-clock surveillance of Russian attack drone operators and rapidly passed collected intelligence to Ukrainian Defense Forces.
Over a months-long campaign in 2025, hacktivists from the Fenix cyber analytics center, with InformNapalm volunteers, allegedly compromised accounts of dozens of Russian military personnel and accessed systems used by attack drone operators.
In the second half of 2025, Russia reportedly deployed repeater systems in Belarus to control attack UAVs, extending strike reach into northern Ukrainian regions including areas from Kyiv to Volyn.
Following the June 1, 2025 strike, Russian authorities reportedly expanded temporary mobile network shutdowns, suggesting recognition that cellular networks were being used as a drone-control channel.
On June 1, 2025, Ukraine reportedly carried out a drone strike on five Russian airfields using public mobile connectivity for telemetry, command, and imagery during the operation.
By 2024, Russian forces had reportedly broadened their use of mobile connectivity from telemetry to include video transmission and command-and-control for drones.
From late 2023, Russian drone use over Ukraine was reportedly observed incorporating public mobile networks, initially for telemetry functions.
By mid-2023, public reporting from Ukraine cited incidents in which drones used SIM-based connectivity for telemetry or activation, indicating early wartime use of mobile networks in drone operations.
Through 3GPP Releases 15 through 18, the mobile industry developed standards for using cellular networks with drones, advancing capabilities for telemetry, command, and data links.
In the mid-2010s, telecom vendors and standards bodies began exploring how public mobile networks could support drone communications, laying groundwork for later battlefield use.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.