Reporting tied to Google’s Threat Intelligence Group (GTIG) and Mandiant describes ongoing nation-state cyber operations affecting critical infrastructure and defense-related targets, including activity attributed to Russian actors in Ukraine and broader campaigns against Western logistics and technology entities. Ukrainian officials said Russian intrusions into the power sector are increasingly used for intelligence collection—such as facility mapping and monitoring repairs—to support or assess missile strikes, rather than purely to cause operational disruption. Separate threat reporting also described China-aligned activity (e.g., UnsolicitedBooker) targeting telecom providers in Kyrgyzstan and Tajikistan using phishing-delivered backdoors (LuciDoor and MarsSnake) capable of command execution and data theft, with some operations leveraging compromised routers for command-and-control.
A technical review of the GTIG/Mandiant reporting identified potential indicator-of-compromise (IOC) quality issues in a prior CISA alert (AA25-141A) that shared overlapping domains, despite the CISA alert being framed around Russian GRU Unit 26165 / APT28. The analysis flagged likely typos that could misdirect defenders—such as accesscan[.]org (suspected to be accesscam[.]org) and glize[.]com (suspected to be giize[.]com or gleeze[.]com)—noting that the corrected-looking domains were associated with dynamic DNS provider Dynu Systems, while glize[.]com appeared to have been a legitimate marketing site. The overlap and possible transcription errors underscore the need for defenders to validate IOCs before enforcement actions (blocking/sinkholing) and to treat government-published indicators as inputs requiring corroboration rather than as authoritative ground truth.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Mandiant's 2025 M-Trends report found that voice phishing rose to become the second most common initial access vector overall and the leading tactic for cloud compromises. The report also highlighted rapid access hand-offs to ransomware actors, long dwell times tied to edge-device abuse, and suspected UNC6201 use of Brickstorm and stolen credentials to persist in VMware environments.
A Netresec analysis identified suspected transcription errors in domain IOCs published by CISA in alert AA25-141A, including accesscan[.]org and glize[.]com. The post warned that such mistakes could misdirect defenders and potentially implicate benign infrastructure, noting overlap with domains cited in Google Threat Intelligence Group and Mandiant reporting.
Researchers observed UnsolicitedBooker targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a geographic and sectoral shift in the cluster's activity. The campaign used phishing emails with malicious Office documents to deploy the LuciDoor and MarsSnake backdoors via associated loaders.
At the Kyiv International Cyber Resilience Forum, Ukrainian officials said Russia uses cyber access before missile attacks to prepare targeting and after attacks to assess strike effectiveness and refine follow-on operations. They said the pattern aligns with recent reporting that Sandworm has prioritized intelligence gathering.
Ukrainian cyber officials said Russian intrusions against energy infrastructure increasingly focused on intelligence collection to support missile strikes rather than causing direct disruption. The activity included mapping facilities, monitoring repair crews, and tracking restoration efforts before and after strikes.
The China-aligned activity cluster UnsolicitedBooker has been active since at least March 2023. Early activity previously focused on entities in Saudi Arabia before later expanding to Central Asian telecommunications targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcenetresec.com
Open sourcevulnu.com
Open sourcescworld.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.