New analysis warns Russia is likely to escalate its opportunistic hybrid activity in Europe into a more coordinated campaign consistent with New Generation Warfare (NGW) doctrine, integrating cyber operations, influence activity, and sabotage across a broader geographic footprint and at higher tempo. The assessment anticipates more synchronized, multi-domain actions designed to degrade NATO cohesion and readiness—such as pairing physical disruption (for example, airspace violations affecting critical infrastructure like airports) with cyberattacks (for example, DDoS against communications) to amplify operational and psychological impact.
Ukrainian officials are simultaneously pushing for tighter regulation of Telegram, citing its repeated use by Russian intelligence to recruit locals for sabotage and terrorist attacks; the calls followed a deadly incident in Lviv that Ukrainian leadership attributed to Russia and said involved recruitment via Telegram. Separately, polling across major NATO countries indicates strong public support for treating severe hybrid actions—such as cyberattacks that shut down hospitals or power grids and sabotage of undersea cables or energy pipelines—as acts of war, highlighting a growing gap between public sentiment and NATO governments’ typically restrained responses to hybrid aggression.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In a Google Cloud blog post published on 2026-06-29, Mandiant said the pro-Russia influence ecosystem had evolved from Ukraine-focused wartime objectives toward broader campaigns targeting the EU, NATO, and other strategic adversaries. The post also highlighted expanded covert influence operations, renewed pro-Russia hacktivism, and increasing use of generative AI to support planning, research, and content creation.
A Recorded Future report published on February 24, 2026 assessed that Russia is likely to escalate over the next two years into a more deliberate Europe-wide hybrid campaign combining cyberattacks, sabotage, influence operations, and infrastructure harassment. The report also outlined mitigations for governments and private-sector critical infrastructure operators.
Following the Lviv attack, senior Ukrainian officials and lawmakers pushed for tighter regulation of Telegram and other anonymous platforms. Proposed responses included limiting app functions, banning the service, or requiring compliance with European regulatory standards.
A POLITICO poll in the United States, Canada, France, Germany, and the United Kingdom found majorities in all five countries believe cyberattacks that shut down hospitals or power grids should be treated as acts of war. The poll also found majority support for classifying sabotage of undersea cables or energy pipelines as acts of war.
An overnight attack in Lviv on February 22 killed a police officer and injured 25 others. President Volodymyr Zelenskyy said Russia organized the attack and that the perpetrators had been recruited via Telegram.
In February 2024, Ukraine’s military intelligence warned that Telegram created security threats. The warning was later cited as an early official concern about the platform’s role in Russian influence and recruitment activity.
Since the 2022 invasion, Russia has conducted increasingly aggressive but largely opportunistic hybrid warfare in NATO countries, including cyber, sabotage, influence activity, and pressure on critical infrastructure. Analysts say these incidents have become more frequent in recent years, including attacks or sabotage involving undersea cables and energy infrastructure.
Russia began its full-scale invasion of Ukraine in February 2022. Subsequent reporting and analysis describe this as the starting point for increasingly aggressive Russian hybrid activity affecting NATO territory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcerecordedfuture.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.