Russia’s Rubikon drone unit emerged as a heavily resourced military formation combining combat operations, research, and training, and became known for using unmanned systems to strike Ukrainian logistics, vehicles, artillery, and drone crews. Reporting says the unit gained influence on multiple fronts and emphasized deep interdiction of supply lines rather than frontline infantry attacks. Its operations reportedly included long-range drone strikes using terminals linked to Starlink, but public disclosure of those tactics prompted SpaceX to disable non-whitelisted terminals in Ukraine, disrupting a key Russian communications channel and reducing the unit’s ability to coordinate such attacks.
The pressure campaign tied to Russia’s war effort has also extended beyond the battlefield into Europe’s defense-industrial base supporting Ukraine. Recent reporting describes Russia-linked espionage, sabotage, intimidation, and possible assassination plotting aimed at drone manufacturers, logistics firms, technology providers, and senior executives, including surveillance of Donaustahl CEO Stefan Thumann and references to an earlier alleged plot against Rheinmetall CEO Armin Papperger. Russian military publication of European drone manufacturers’ addresses and GRU-linked cyber activity targeting shipment schedules, routes, manifests, and cargo details point to a broader effort to disrupt the people, companies, and supply chains sustaining military aid to Ukraine.

TTPs, infrastructure, and targeting history in one profile.
13 events from the most recent confirmed update back to the earliest known activity.
In April 2026, Russia’s Ministry of Defense publicly released the addresses of European drone manufacturers supporting Ukraine, an action the article assesses as target signaling and intimidation.
The article says Rubikon alone conducted 48,500 combat sorties in January 2026 and struck about 1,300 Ukrainian personnel and nearly 1,000 vehicles and armored vehicles that month.
Canada sanctioned Rubikon leader Colonel Sergey Budnikov in November 2025 for supporting Russia’s invasion of Ukraine.
Rubikon’s logistics interdiction campaign on the Sumy-Kursk border continued into March 2025, with Ukrainian sources and analysts describing it as an important factor in pressuring Ukrainian positions.
According to the article, Rubikon’s operations against Ukrainian logistics on the Sumy-Kursk border in February and March 2025 contributed to Ukraine’s withdrawal from its Kursk foothold.
At the end of 2025 and beginning of 2026, Rubikon began publishing videos of long-range strikes conducted 100 to 240 kilometers from the front using drones equipped with Starlink terminals.
German authorities reportedly investigated surveillance of Donaustahl CEO Stefan Thumann and his family in late 2025 and early 2026, including alleged filming of his home and efforts to identify his whereabouts through family members.
The article says Rubikon began using and developing unmanned surface vessels from summer 2025, expanding beyond aerial drone operations.
The first public videos showing Rubikon’s combat activity appeared in October 2024, marking its public emergence as a Russian military drone formation.
Russia’s Ministry of Defense says the Experimental Center for Advanced Unmanned Technologies Rubikon was created in August 2024 by decision of Defense Minister Andrei Belousov, based on an existing drone unit.
Western officials warned in 2024 that Russia was conducting sabotage across Europe, including arson, vandalism, and assassination plots.
In 2024, U.S. intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall CEO Armin Papperger, cited as part of a broader Russia-linked campaign against European defense support for Ukraine.
After videos of Rubikon’s long-range strikes appeared, SpaceX blocked non-whitelisted Starlink terminals on the territory of Ukraine, according to the article. Ukrainian military sources said the deactivations disrupted Russian command and control and caused pauses in assault operations on some sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcebbc.com
Open sourcesvoboda.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.