Western governments, investigators, and private-sector researchers have linked Russia’s GRU, including Unit 26165 and other associated officers, to a broad campaign of cyber intrusions, destructive malware operations, and close-access hacking against political, diplomatic, and critical targets. Public reporting tied Unit 26165—also known as Fancy Bear—to the 2018 attempted compromise of the OPCW in The Hague, where Dutch authorities disrupted four Russian operatives allegedly equipped to target the organization’s Wi‑Fi network, and to earlier operations against anti-doping bodies and the device of Yulia Skripal using X-Agent malware. CrowdStrike previously attributed the intrusion into the Democratic National Committee to Russian actors associated with the same broader threat cluster.
U.S., UK, and independent disclosures have expanded that picture by naming individual GRU officers and units allegedly involved in attacks on Ukrainian critical infrastructure, France’s Macron campaign, the 2018 Winter Olympics, NotPetya victims, and reconnaissance that supported missile strikes on Mariupol, including the theatre attack. In 2020, the FBI publicized charges against six GRU officers for destructive malware and international cyberattacks, while Bellingcat used leaked Russian vehicle registration data to connect several indicted hackers to known GRU addresses tied to Unit 74455 and related military intelligence infrastructure. The UK later imposed sanctions on multiple GRU units and 18 officers, describing the activity as part of a long-running Russian cyber and hybrid campaign against Ukraine, the UK, and other countries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On July 18, 2025, the UK announced sanctions against three GRU units and 18 Russian military intelligence officers for a long-running campaign of malicious cyber and hybrid activity. The action also sanctioned three leaders of African Initiative, which the UK described as a Russia-funded information operation platform in West Africa.
The UK government said GRU Unit 26165 conducted online reconnaissance in 2022 that helped target missile strikes against Mariupol, including the strike that destroyed the Mariupol Theatre. The UK said the theatre attack killed hundreds of civilians, including children.
Bellingcat reported on October 22, 2020 that leaked Moscow vehicle registration data linked several indicted GRU hackers to known GRU addresses, including Svobody 21V and Khoroshevskoe 76B. The analysis identified 49 people registered to variants of the Svobody 21 address, suggesting a broader pool of GRU-associated personnel.
On October 15, 2020, a federal grand jury in the Western District of Pennsylvania returned an indictment against six Russian military intelligence officers for destructive malware operations and other disruptive cyberattacks worldwide. The alleged targets included Ukrainian critical infrastructure, France's political campaign, Georgia, NotPetya victims, the Winter Olympics, and investigations into nerve agent attacks attributed to Russia.
On 2018-10-04, the UK's National Cyber Security Centre publicly attributed attacks on WADA, the DNC, Ukrainian critical infrastructure, and the OPCW to the GRU, identifying it with APT28 and stating high confidence. Canada the same day blamed the GRU for attacks on WADA and the Canadian Centre for Ethics in Sport and supported the Dutch attribution over the OPCW operation.
On October 4, 2018, a federal grand jury in the Western District of Pennsylvania indicted seven alleged GRU officers for a conspiracy spanning about December 2014 through at least May 2018. The charges covered hacking, wire fraud, aggravated identity theft, and money laundering tied to intrusions against anti-doping organizations, athletes, Westinghouse Electric Company, and the OPCW, as well as leak-and-amplification activity through the Fancy Bears persona.
On October 4, 2018, the Netherlands publicly disclosed the disrupted OPCW operation and identified the four operatives. A US Department of Justice indictment issued the same day linked Aleksei Morenets and Evgenii Serebriakov to GRU Unit 26165.
On July 13, 2018, a U.S. grand jury charged 12 Russian citizens described as GRU employees with interfering in the 2016 U.S. presidential election through cyberattacks on Democratic Party figures and the publication of stolen information. The indictment identified officers from GRU units 26165 and 74455 and tied them to personas including Guccifer 2.0 and DCLeaks.
On April 10, 2018, four Russian nationals arrived at Amsterdam Schiphol Airport carrying diplomatic passports and were met by a member of the Russian embassy in The Hague. They carried technical equipment and conducted surveillance of OPCW headquarters as part of an apparent effort to hack the organization’s systems.
Dutch intelligence intercepted the four Russian operatives targeting the OPCW in The Hague and sent them back to Moscow. The apparent objective was to compromise OPCW systems and disrupt investigations related to the Skripal poisoning.
The article states that GRU Unit 26165 was also linked to hacking World Athletics in 2017.
According to the DOJ indictment cited in the content, Aleksei Morenets and Evgenii Serebriakov traveled to Rio de Janeiro and Lausanne in 2016 to target Wi‑Fi networks used by people with access to USADA, WADA, and the Canadian Center for Ethics in Sport.
The content states that GRU Unit 26165 had previously been known for remote intrusions, including the 2016 Democratic National Committee breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
gov.uk
Open sourceatlanticcouncil.org
Open sourcebellingcat.com
Open sourcecyberscoop.com
Open sourcejustice.gov
Open sourcerferl.org
Open sourcejustice.gov
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.