U.S. and allied officials have tied multiple high-profile cyber incidents to Russian-linked actors, including the SolarWinds espionage campaign, follow-on targeting of roughly 150 organizations flagged by Microsoft, and newer phishing operations aimed at Signal and WhatsApp users. The activity has also intersected with politically sensitive investigations, including an FBI review of claims that hacked files were involved in a Trump campaign-related incident, underscoring how state-aligned intrusion and influence operations continue to overlap with espionage and credential theft.
At the same time, Russian-speaking cybercriminal ecosystems have remained a major source of disruption through ransomware and fraud. A prominent Russian-speaking ransomware gang was reported to have gone offline, even as ransomware attacks hit public-sector and healthcare victims including Dallas police and court websites and MedStar hospitals. Separate financially motivated operations also showed the breadth of the threat landscape, from the takeover of high-profile Twitter accounts in a bitcoin scam to large-scale phishing campaigns impersonating E-ZPass and USPS, prompting legal action by Google against an alleged Chinese scam ring.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Dutch officials warned that a Russian-linked campaign was using phishing techniques to target users of Signal and WhatsApp, aiming to compromise accounts and gain access to sensitive communications.
Google sued operators it said were behind a large phishing campaign that impersonated toll agencies and the U.S. Postal Service in scam text messages designed to steal victims' personal and payment information.
The Trump campaign said hacked files had been obtained, and the FBI confirmed it was investigating the matter, marking a federal response to the alleged intrusion involving campaign-related materials.
A ransomware attack affected the City of Dallas, knocking police and court-related websites offline and disrupting some municipal services while officials investigated and worked to restore systems.
A prominent Russian-speaking ransomware gang's infrastructure and public-facing sites went offline, suggesting disruption or a strategic retreat amid heightened international law-enforcement and political pressure.
Microsoft said the Russian-linked group behind the SolarWinds espionage campaign was conducting a new wave of attacks and had targeted roughly 150 organizations, many involved in foreign policy and humanitarian work.
In the days following disclosure of the SolarWinds breach, the company's stock dropped about 23% as investors reacted to the scale and seriousness of the compromise.
SolarWinds disclosed that attackers had inserted malicious code into Orion software updates, enabling a broad espionage campaign affecting U.S. government agencies and private-sector organizations.
Attackers compromised prominent Twitter accounts, including those of Bill Gates and Elon Musk, and used them to post fraudulent bitcoin giveaway messages. The incident exposed weaknesses in Twitter's internal administrative controls.
MedStar Health suffered a ransomware attack that disrupted computer systems across its hospitals and forced staff to rely on paper records and manual procedures while recovery efforts began.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
nbcnews.com
Open sourcenbcnews.com
Open sourcenbcnews.com
Open sourcenbcnews.com
Open sourcenbcnews.com
Open sourcenbcnews.com
Open sourcenbcnews.com
Open sourcecnbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.