Russian state-backed cyber operations have intensified against Western democracies, with the United Kingdom and Moldova reporting significant hostile activities attributed to Kremlin-linked actors. In the UK, the former head of MI5, Baroness Manningham-Buller, publicly stated that the scale and nature of Russian cyberattacks, intelligence operations, and physical sabotage suggest the country may already be engaged in a form of warfare with Russia. She highlighted the extensive use of cyberattacks, intelligence collection, and physical attacks, referencing recent campaigns attributed to APT28, a group linked to Russia's GRU, which targeted Microsoft login credentials and passwords as part of espionage efforts. The UK's National Cyber Security Centre (NCSC) has issued warnings about these campaigns, noting that Russian hacking groups have focused on governments, technology firms, and logistics suppliers supporting Ukraine. These operations are not isolated, as Russian state-backed cyberattacks have targeted Western organizations for years, often in coordination with ransomware gangs and cybercriminals believed to have ties to Moscow's intelligence services. In Moldova, Deputy Prime Minister Doina Nistor accused Russia of orchestrating a cyberattack on the Central Electoral Commission ahead of parliamentary elections, describing it as part of a broader hybrid campaign to destabilize the country's democracy. The attack exploited a vulnerability that has since been secured, but officials warn that Moldova is being used as a testbed for Russian hybrid warfare tactics, including DDoS attacks via hijacked routers, AI-driven disinformation, and efforts to radicalize youth and orchestrate unrest. Moldovan authorities report that the scale of Russian interference now far exceeds previous years, with increased funding for vote-buying, more sophisticated disinformation campaigns, and greater resources dedicated to destabilizing the electoral process. These hybrid operations are seen as a warning for other Western democracies, with officials cautioning that successful tactics in Moldova could soon be deployed in upcoming elections across Europe and the United States. The overarching goal of these Russian operations is to manipulate public opinion, undermine trust in democratic institutions, and destabilize governments. Both the UK and Moldova have responded by strengthening cybersecurity measures and raising public awareness, but the persistent and evolving nature of Russian hybrid threats continues to pose a significant challenge to national security and democratic integrity across the West.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A former head of MI5 publicly suggested that the UK may already effectively be at war with Russia, reflecting escalating concern over hostile Russian cyber and influence operations. The remarks underscored the growing view that cyber activity is part of a broader state conflict environment.
Moldova held a vote that resulted in a pro-EU outcome, despite reported Russian influence activity surrounding the process. The result highlighted concerns that future Moldovan elections could face continued foreign interference and cyber-enabled influence risks.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.