APT29 (Midnight Blizzard / Cozy Bear)
Russian state-sponsored threat actor attributed to the SVR, known for long-term cyber espionage campaigns. In this campaign, its sub-cluster Storm-2945 is linked…
Russian state-sponsored threat actor attributed to the SVR, known for long-term cyber espionage campaigns. In this campaign, its sub-cluster Storm-2945 is linked…
F6, a Russian cybersecurity company, disclosed a large-scale fraud campaign involving clone websites of major Russian companies to steal advance payments from…
The Federal Security Service of the Russian Federation (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and failing to…
TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits…
UAC-0099 is a Russia-aligned threat cluster tracked by CERT-UA, active since at least mid-2022. It has used phishing emails and exploits in…
UAC-0145 is a sub-cluster within the Sandworm advanced hacking unit, affiliated with Russia's GRU. It has been attributed by CERT-UA to campaigns…
The GRU is Russia's primary foreign military intelligence agency, which sponsors advanced hacking units like Sandworm and its sub-clusters such as UAC-0145.
A cyber division of Russia's Main Intelligence Directorate (GRU) known for recruiting hackers and cyber specialists from Russian universities, collaborating with cybercriminals…
A unit of the Russian Federal Security Service (FSB) attributed to disruptive sabotage operations, including against Poland's energy grid. Exploits poorly configured…
A company linked to GRU Unit 29155, involved in recruiting hackers and cyber specialists from Russian universities for cyber operations. Sanctioned by…