Russian and China-linked threat activity has relied on common but effective entry points to penetrate government, telecom, defense, energy, and other critical-sector networks. Ukrainian officials said CERT-UA recorded 5,927 cyber incidents in 2025, a 37.4% increase over the prior year, with Russian groups including UAC-0002 (Sandworm), UAC-0001 (APT28), UAC-0010 (Gamaredon), and UAC-0190 (Void Blizzard) using exposed RDP services, vulnerable VPN appliances, supply-chain compromise, phishing, and stolen credentials to gain access. Separately, telecom intrusions tied to the China-linked cluster UAT-9244 used exposed web applications, ProxyLogon, exposed SSH services, weak credentials, and unpatched server software to establish footholds in Linux-heavy environments.
Once inside, the actors deployed a broad toolset for espionage, persistence, and disruption, including RATs, stealers, ransomware, wipers, and Linux malware such as PeerTime, which supports multiple architectures and uses peer-to-peer, BitTorrent-like communications to avoid reliance on centralized command-and-control. The reporting highlights exploitation of products including Cisco ASA/AnyConnect, Roundcube, Fortinet, WinRAR, 7-Zip, and legacy Microsoft Office components, alongside social-engineering tactics such as ClickFix, device-code phishing, OAuth phishing, and QR-code hijacking. The campaigns also abused legitimate services and native system tools, while under-monitored embedded Linux devices, routers, edge systems, and container hosts were described as especially attractive for long-term persistence, lateral movement, scanning, and covert communications.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A Linux malware payload called PeerTime was highlighted as supporting multiple architectures including ARM, AArch64, MIPS, PowerPC, and x86, suggesting targeting of embedded appliances, routers, and virtualized infrastructure. The malware reportedly uses peer-to-peer and BitTorrent-like traffic patterns and checks for Docker before execution, indicating an effort to persist in modern enterprise and telecom environments.
Recent telecom-focused intrusions associated with the China-linked cluster UAT-9244 were reported as using exposed web applications, ProxyLogon exploitation, exposed SSH services, weak credentials, and unpatched server-side software for access. The operations emphasized persistence and infrastructure abuse rather than novel exploitation.
CERT-UA published a report on the second half of 2025 stating that the number of cyber incidents had decreased, while attackers increasingly relied on more sophisticated social engineering and more standardized toolkits. The report added an official Ukrainian assessment of changing threat quality during late 2025 rather than only overall annual volume.
Google Cloud/Mandiant published a threat-intelligence report detailing cyber threats affecting the defense industrial base, adding a distinct disclosure focused on DIB-targeting activity. This represents a new reporting development separate from the existing Ukraine-wide and telecom-focused entries.
During 2025, Russian state-sponsored groups including UAC-0002 (Sandworm), UAC-0001 (APT28), UAC-0010 (Gamaredon), and UAC-0190 (Void Blizzard) intensified operations using exposed RDP, VPN vulnerabilities, supply-chain compromise, phishing, messaging-app lures, and brokered stolen credentials for initial access. Reported exploitation included flaws in Cisco ASA/AnyConnect, Roundcube, Fortinet, WinRAR, 7-Zip, and legacy Microsoft Office, alongside social-engineering techniques such as ClickFix, Device Code phishing, OAuth phishing, and GhostPairing QR-code hijacking.
Ukraine’s CERT-UA recorded about 5,927 cyber incidents in 2025, representing a 37.4% increase over 2024. The activity was described as deliberate and persistent, with government, defense, energy, and other critical sectors in Ukraine and across Europe heavily targeted.
Ukraine's CERT-UA disclosed that the Russian state-backed Sandworm group had compromised 11 Ukrainian telecommunications providers since May 2023. The intrusions targeted telecom infrastructure during the war, marking a specific campaign against Ukraine's communications sector.
CISA issued alert TA18-074A describing Russian government cyber activity targeting U.S. energy, nuclear, commercial facilities, water, aviation, and other critical infrastructure sectors. The alert publicly documented intrusion tactics and warned that the activity enabled access to operationally sensitive networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcelinuxsecurity.com
Open sourcecip.gov.ua
Open sourcecip.gov.ua
Open sourcebleepingcomputer.com
Open sourceus-cert.cisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.