Cyber operations tied to Russia’s invasion of Ukraine ranged from destructive malware and espionage to broader disruption against Ukrainian and allied targets. Researchers and government agencies documented WhisperGate, HermeticWiper, CaddyWiper, DoubleZero, and FoxBlade activity against Ukrainian networks, while Microsoft said it seized seven Strontium domains used to target Ukrainian institutions, media, and foreign-policy organizations in the U.S. and EU. Talos also reported a campaign against a Ukrainian software developer using a modified GoMet backdoor, raising supply-chain concerns, and Symantec described sustained Shuckworm/Gamaredon espionage using multiple Pterodo variants for persistence. Later reporting warned that Russian operations were expanding beyond Ukraine to logistics, transportation, defense, and energy organizations supporting Kyiv, including activity in Poland and across Europe’s defense supply chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
52 events from the most recent confirmed update back to the earliest known activity.
Truesec said Russia's Ministry of Defense publicly released the addresses of European drone manufacturers supporting Ukraine in April 2026, which it assessed as target signalling and intimidation.
HarfangLab said it identified roughly a dozen waves of Gamaredon spearphishing emails targeting Ukrainian state institutions dating back to September 2025.
Truesec reported that German authorities investigated surveillance of Donaustahl CEO Stefan Thumann and his family in late 2025 and early 2026, including filming his home and trying to identify his whereabouts through relatives.
On September 5, 2024, the UK NCSC and nine allied partners publicly attributed a global malicious cyber campaign to Russia's GRU Unit 29155 and specifically blamed it for deploying WhisperGate before the 2022 invasion.
Truesec reported that U.S. intelligence helped Germany disrupt a Russian plot against Rheinmetall CEO Armin Papperger in 2024.
Truesec said Western officials warned in 2024 that Russia was conducting sabotage across Europe, including arson, vandalism, and assassination plots tied to support for Ukraine.
Microsoft said that in October 2022, IRIDIUM deployed the novel Prestige ransomware against logistics and transportation sector networks in Poland and Ukraine, marking a war-related attack outside Ukraine since the Viasat incident.
Microsoft said that in October 2022, IRIDIUM's destructive attacks against Ukrainian critical services networks increased after two months of little to no wiper activity.
CERT-UA reported that the intermediate .NET program "MCMDiction.exe" used in the same phishing chain had a compilation date of July 8, 2022.
CERT-UA reported that the AgentTesla payload used in the Operational Command "South" phishing chain had a compilation date of July 6, 2022.
The NCSC said that in May 2022, the UK and allies attributed WhisperGate activity in Ukraine to Russia's military intelligence service, before later narrowing it to GRU Unit 29155.
On April 6, 2022, Microsoft obtained a court order to take control of seven domains used by the GRU-connected actor Strontium and redirected them to a Microsoft sinkhole to block ongoing attacks and notify victims.
Microsoft said IRIDIUM attempted in April 2022 to damage the industrial control systems of a Ukrainian energy provider, but CERT-UA and international partners thwarted the attack.
Talos said it first observed the GoMet malware campaign on March 28, 2022 targeting a large Ukrainian software development company whose software is used by state organizations.
Kaspersky's GReAT shared insights on cyberattacks in Ukraine during a webinar held on March 10, 2022, covering APT activity, DDoS, hacktivism, cybercrime, and destructive malware.
Microsoft said it was taking steps to reduce Russian state propaganda by no longer displaying RT and Sputnik content on Microsoft Start and MSN.com in line with an EU decision, removing RT apps from the Windows app store, downranking RT and Sputnik in Bing, and banning their advertising across its ad network.
Threatpost reported that Brad Smith said on Monday, February 28, 2022, that the precisely targeted cyberattacks involving FoxBlade were still ongoing.
eSentire said Ukrainian border control was reportedly infected with HermeticWiper on February 27, 2022, disrupting refugee crossings into Romania.
Trend Micro reported that the Conti ransomware group announced on February 25, 2022 that it fully supported the Russian government and threatened to strike back against anyone organizing cyberattacks or war activities against Russia. The group later softened the wording of its original pro-Russia statement on its leak site.
After discovering FoxBlade on February 24, 2022, Microsoft informed the Ukrainian government, provided technical advice, and pushed new Microsoft Defender signatures within three hours.
Microsoft detected a new round of offensive and destructive cyberattacks against Ukraine's digital infrastructure on February 24, 2022, several hours before Russia's invasion, and identified the novel FoxBlade trojan.
Microsoft said IRIDIUM was responsible for the wave of destructive cyberattacks against Ukrainian targets that began on February 23, 2022, ahead of the invasion.
eSentire said ESET researchers first detected HermeticWiper on February 23, 2022 at 10 a.m. EST. The malware was later reported as installed on hundreds of machines in Ukraine.
On February 15, 2022, a massive DDoS attack disrupted Ukraine's two largest banks. The incident also affected mobile banking applications and ATMs, expanding the impact beyond government entities to the financial sector.
eSentire said DDoS attacks against Ukrainian government agencies had reportedly been ongoing since February 15, 2022, affecting entities including the Cabinet of Ministers, Verkhovna Rada, Security Service of Ukraine, and Ministry of Foreign Affairs.
Microsoft published findings that the Russia-aligned ACTINIUM threat actor was targeting Ukrainian organizations. The disclosure added a separate actor and campaign to the pre-invasion threat activity already documented against Ukraine.
Microsoft reported that the WhisperGate campaign began on January 13, 2022. The malware masqueraded as ransomware but functioned as a destructive wiper.
Cisco said it increased monitoring in Ukraine more than a month before Russia's invasion and, after the mid-January website defacements and first WhisperGate deployments, began incident-response support for three Ukrainian government agencies. The company said it translated those findings into tailored protections for Ukrainian networks and broader defenses for customers globally.
Reporting on HermeticWiper noted that one sample carried a compilation timestamp of December 28, 2021, indicating the destructive malware had likely been prepared well before deployment.
Talos assessed that the actors behind the fake pro-Ukraine tool campaign had been distributing infostealers since at least November 2021 and later repurposed the war theme to lure victims.
Talos said the self-signed certificate used by the GoMet campaign's command-and-control IP was issued on April 4, 2021, suggesting preparation may have begun as early as then.
The UK NCSC and allies said GRU Unit 29155 had conducted malicious cyber operations since at least 2020, including espionage, defacement, and destructive sabotage.
Talos said the original open-source GoMet backdoor source code was posted on GitHub on March 31, 2019, with commits continuing until April 2, 2019.
Intel 471 said Andrey Novak, later reported arrested in Russia, had been charged in absentia by the U.S. Department of Justice in connection with Infraud.
Microsoft cited IRIDIUM's 2017 NotPetya attack as causing an estimated $10 billion in global damage, affecting companies including Maersk, Merck, and Mondelēz.
Microsoft said its disruption effort against the GRU-connected actor Strontium began in 2016 and eventually enabled repeated court-authorized infrastructure seizures.
Microsoft said IRIDIUM, tracked by others as Sandworm, carried out attacks against Ukrainian electricity providers in 2015 and 2016 that cut power to hundreds of thousands of citizens.
Symantec said the Russian-linked Shuckworm group, also known as Gamaredon or Armageddon, has focused almost exclusively on organizations in Ukraine since it first appeared. Microsoft separately noted that IRIDIUM/Sandworm had targeted Ukrainian critical energy infrastructure since at least 2014.
CERT-UA disclosed a cyberattack against Ukrainian government organizations using a malicious PowerPoint file themed around Operational Command "South" that ultimately executed AgentTesla.
Symantec reported that Shuckworm was continuing an intense espionage campaign against Ukraine and had recently deployed four distinct Pterodo variants on victim systems to improve persistence and resilience.
BleepingComputer reported that Malwarebytes uncovered a spear-phishing campaign targeting Russian government employees and public servants opposed to the state's narrative on the war, delivering Cobalt Strike and a PowerShell RAT.
Talos said it updated the IOC section for the fake pro-Ukraine tool campaign on March 17, 2022 with additional hashes and ClamAV coverage.
Cisco Talos reported an opportunistic campaign on Telegram in which a file posing as the "Liberator" DDoS tool actually installed the Phoenix information stealer and exfiltrated credentials and cryptocurrency data.
Microsoft reported a limited destructive attack in early March 2022 affecting a single Ukrainian entity, using Golang malware it named DesertBlade. The company said the malware was deployed via hijacked Group Policy Objects and provided hashes and a YARA rule for detection.
Bitdefender said email-based charity scams exploiting support for Ukraine peaked on March 2, 2022, including a cryptocurrency donation scam that reached tens of thousands of inboxes.
Bitdefender said it observed a second malspam campaign on March 2, 2022 impersonating a South Korean healthcare company and using the Excel attachment "SUCT220002.xlsx" to deliver Remcos RAT.
Bitdefender said it tracked a phishing campaign beginning March 1, 2022 that targeted manufacturing organizations with a ZIP attachment named "REQ Supplier Survey" and delivered Agent Tesla from Discord.
Bitdefender Antispam Lab reported signs on February 25 that scammers were exploiting Russia's invasion of Ukraine and the refugee crisis in email fraud campaigns.
Microsoft said the February 24, 2022 cyberattacks involving FoxBlade hit Ukrainian civilian organizations in finance, agriculture, emergency response, humanitarian aid, and energy. It also warned of attempts to steal government-held data, including healthcare, insurance, transportation, and other personally identifiable information.
Intel 471 reported that over the prior three months, Ferum Shop, Trump Dumps, UAS Shop, and Sky Fraud went offline with notices claiming seizure by Russia's Ministry of Internal Affairs, alongside arrests of six individuals reported by TASS.
Secureworks said the WhisperGate timing coincided with defacements of Ukrainian government websites, and Ukrainian authorities reported that more than 70 government sites were attacked with unauthorized access on 10 of them.
Palo Alto Networks Unit 42 reported technical findings connecting WhisperGate-related activity in Ukraine to exploitation of CVE-2021-32648. The disclosure added a specific intrusion vector and technical detail to the previously documented WhisperGate campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
32 references tracked. Mallory keeps watching after this page renders.
truesec.com
Open sourceintel471.com
Open sourceharfanglab.io
Open sourcesecureworks.com
Open sourcezdnet.com
Open sourcebitdefender.com
Open sourceunit42.paloaltonetworks.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.