Denmark has raised its threat level for destructive cyberattacks from medium to high, citing intelligence assessments that Russia is increasingly likely to conduct hybrid activity, including disruptive cyber operations, against Denmark and other NATO members in the coming months. Authorities warned that wiper malware and attacks on operational technology (OT) pose particular risks to critical infrastructure, referencing a late-2024 attack on a Danish waterworks and a disrupted December 2025 attempt against Poland’s energy sector; public agencies and critical-function operators were urged to strengthen incident planning, cyber resilience, and OT defenses.
Recorded Future’s Insikt Group reported that Russia has expanded its “New Generation Warfare” across Europe since the invasion of Ukraine, combining cyberattacks, influence operations, physical sabotage, and airspace and maritime incursions. Reported incidents include an explosive drone at Leipzig/Halle Airport, a maritime drone near Romania’s Neptun Deep gas project, attacks on Norwegian public-sector portals, and Russian drones near Estonia. The group assesses that such activity will likely intensify over the next two years, elevating the risk of data loss, service disruption, facility damage, and danger to personnel, while judging Moscow is unlikely to intentionally trigger NATO Article 5 through mass casualties or permanent infrastructure destruction.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
The German government publicly blamed Russia for an alleged sabotage plot at Leipzig/Halle Airport. Police recovered drones carrying military-grade hexogen explosives intended to damage cargo infrastructure at the logistics hub supporting German aid to Ukraine.
Estonian defense forces tracked multiple Russian drones near the Estonian border, including one that entered southeastern Estonian airspace; NATO F-16s at Ämari Air Base were scrambled.
Russia-nexus cyber threat actors reportedly conducted coordinated attacks against Norwegian public-sector infrastructure, forcing key government portals offline. Norwegian authorities characterized the activity as retaliation for Norway's military support to Ukraine.
Romanian authorities intercepted and destroyed an explosive-laden Russian surface maritime drone near the Neptun Deep offshore gas project, assessing it was intended to threaten energy infrastructure and test NATO maritime-response protocols.
The CopyCop disinformation network reportedly expanded by impersonating local news and fact-checking outlets, particularly in France and Norway, using AI-generated text and cloned voices.
Polish authorities thwarted a large-scale attack against the country's energy sector; the Polish government subsequently assessed Russia was responsible.
Insikt Group tracked 30 suspected NATO-airspace violations by likely Russian drones or jets between September 2025 and January 2026, compared with 23 suspected or confirmed violations from March 2022 through August 2025.
The Polish government attributed the fire at Warsaw's Marywilska 44 shopping center to Russian intelligence services.
Pro-Russian actors reportedly connected to the Russian state compromised a small Danish waterworks' OT system, manipulated water pressure, and temporarily interrupted supply to about 450 households.
Russia-linked physical sabotage operations increased fourfold from 2023 to 2024, with civilian and dual-use infrastructure in NATO territory increasingly targeted.
Russia launched its full-scale invasion of Ukraine, after which its hybrid and asymmetric activity expanded across Europe.
Russia employed NGW tactics in Ukraine during and after its annexation of Crimea.
Russian military officials described the New Generation Warfare (NGW) concept, which combines psychological, cyber, and physical tactics.
Denmark's Agency for Social Security raised the national threat level for destructive cyberattacks from medium to high, citing FE and PET assessments of increasing Russian hybrid activity and indications of concrete sabotage planning targeting Denmark.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecert.dk
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.