Alpha Cyber
NewsTLP:CLEAR

Russian Hackers Are On The Rise !

As the war in Ukraine enters its fourth month, the battlefield has expanded beyond conventional warfare into cyberspace.

Alpha Cyber Research2 min readupdated 8 Jul 2025
Russian Hackers Are On The Rise !

As War Rages in Ukraine, the World Braces for Russian APT Attacks

As the war in Ukraine enters its fourth month, the battlefield has expanded beyond conventional warfare into cyberspace. Russia-based cyberattacks have devastated Ukrainian infrastructure and are increasingly targeting the nation’s allies.
Several weeks ago, a joint cybersecurity advisory issued by the governments of the United States, Canada, the United Kingdom, Australia, and New Zealand warned organizations globally of the heightened cyber threat posed by Russia. At the time, it was anticipated that a new wave of attacks against Ukraine’s allies would soon follow, and indeed, several significant cyber incidents have since been reported.

When assessing the digital threat landscape, it’s critical to understand the role of state-sponsored Advanced Persistent Threat (APT) groups, many of which are backed by the Kremlin. These sophisticated threat actors are among the most dangerous in the world:

Fancy Bear (APT28), Also known as Pawn Storm, Sofacy Group, STRONTIUM, and others, this cyber-espionage group has a long history of attacks dating back to 2014. Notable operations include a six-month cyber assault on the German parliament, attacks on journalists across multiple nations, the 2015 TV5Monde breach, and the infamous 2016 spear-phishing campaign against the U.S. Democratic National Committee.

Cozy Bear (APT29), Linked to either the Russian FSB or SVR, Cozy Bear (also known as NOBELIUM and Dark Halo) is notorious for high-profile breaches, including the 2015 phishing attack that disabled the Pentagon’s email system, spear-phishing operations against U.S. think tanks, and the unprecedented SolarWinds supply chain attack.

Sandworm (Unit 74455), Operating under aliases like Telebots and Iron Viking, Sandworm is infamous for cyber operations targeting critical infrastructure. Their most notable actions include the December 2015 Ukrainian power grid attack and the 2022 deployment of Cyclops Blink malware. In 2020, several Sandworm members were indicted by a U.S. grand jury for cybercrimes ranging from wire fraud to aggravated identity theft.

Berserk Bear, Also known as Crouching Yeti and Dragonfly, this group is believed to consist of FSB-affiliated hackers and coerced civilian cybercriminals. Specializing in attacks on utilities and industrial control systems, they represent one of the most dangerous threats to critical infrastructure globally.

It’s important to note that the cyber threat landscape extends beyond Russia. Dozens of APT groups associated with China, North Korea, Iran, and other nations actively conduct cyber operations. As geopolitical tensions rise and alliances shift, particularly with the deepening cooperation between Russia and China. The likelihood of broader, state-sponsored cyber warfare escalates.

Thanks to Rebellion Research for this insightful article.

Keep reading

Related research

Your Phone is a Narc
News

Your Phone is a Narc: The Systematic Betrayal of Civilian Privacy

Deep Dive // Surveillance Capitalism PUBLISHED: MAY 2026 Your Phone Is a Narc: The Built-In Infrastructure Betraying Civilian Privacy How everyday smartphones are weaponized against civilians without a single line of malware, turning features into informants.

3 min read

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]