U.S. prosecutors unsealed an indictment accusing a Russian intelligence-linked RIS Network of directing surveillance, assassination, and sabotage operations across Europe and the United States. The alleged network recruited operatives to target Russian dissidents, offered payments for attacks on NATO-related electrical infrastructure in countries supporting Ukraine, and was linked to an attempted June 2024 arson attack on a Prague bus depot and a planned September 2024 attack in Lithuania. Five defendants—including former Russian intelligence colonel Yuri Khrameev, FSB officer Kirill Khrameev, and logistics coordinator Oemis Romagoza Durruthy—remain at large on U.S. terrorism-financing charges.
Separately, reporting indicates Russia-linked actors have approached participants in “The Com,” a largely Western online ecosystem containing violence-for-hire and cybercriminal subcommunities, to recruit young people as disposable agents for sabotage missions. Recruitment reportedly occurs through online platforms including Telegram and forms part of a broader hybrid campaign intended to weaken European backing for Ukraine; at least two UK attacks have reportedly been tied to Russia-linked actors. The reporting found no indication that Russian intelligence has recruited the distinct Hacker Com segment, despite activity in overlapping online spaces.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Andrés Alfonso de la Hoz de la Cruz, identified by Novinky.cz as the Prague arson attacker, reportedly pleaded guilty and was sentenced to eight years in prison for the attack.
Oemis Romagoza Durruthy allegedly continued logistical coordination for a separate attack in Lithuania on behalf of the RIS Network.
The alleged RIS Network was linked to an attempted arson at a Prague public-transport bus depot. Czech authorities arrested the alleged attacker, while logistics coordinator Oemis Romagoza Durruthy allegedly sent more than $1,000 in cryptocurrency and booked hotels for the operation.
Russia-linked actors reportedly contacted elements of The Com and sought to recruit teenagers as disposable agents for sabotage operations, amid a wave of European attacks linked to Russian recruitment activity. The reporting associated at least two attacks in the United Kingdom with Russia-linked actors, while stating there was no indication that Russian intelligence had approached the separate Hacker Com segment.
A newly unsealed U.S. federal indictment charged five alleged members of the Russian intelligence-linked RIS Network with conspiracy to finance terrorism. It alleged the network directed sabotage, surveillance, assassination, and murder-for-hire activity in Europe and the United States, including targeting infrastructure in countries supporting Ukraine.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetruesec.com
Open sourceoccrp.org
Open sourceinews.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.