Articles tagged Russia
-
Campaign2015 Ukraine Electric Power Attack
Sandworm Team's use of BlackEnergy3 and KillDisk to disrupt transmission and distribution substations within the Ukrainian power grid in December 2015 — the first major public cyberattack on a power grid.
-
Campaign2016 Ukraine Electric Power Attack
Sandworm Team's use of Industroyer malware to target and disrupt distribution substations within the Ukrainian power grid in December 2016, the second major public attack Sandworm Team conducted against Ukraine.
-
CampaignAPT28 Nearest Neighbor Campaign
APT28's use of Wi-Fi daisy-chaining across nearby compromised organizations, combined with zero-day exploitation of CVE-2022-38028, to reach organizations and individuals with Ukraine expertise, February 2022 to November 2024.
-
Campaign2025 Poland Wiper Attacks
Russian state-sponsored destructive campaign against Polish energy infrastructure in December 2025, deploying two previously undocumented wiper tools against wind, photovoltaic, and CHP facilities.
-
Threat ActorAPT28
State-sponsored APT group targeting NATO-aligned governments, defense contractors, and critical infrastructure.
-
Threat ActorAPT29
Threat group attributed by MITRE ATT&CK to Russia's Foreign Intelligence Service (SVR), active since at least 2008 and linked to the 2015-16 DNC compromise and the 2020 SolarWinds supply-chain attack.
-
Threat ActorTurla
Cyber espionage group attributed by MITRE ATT&CK to Russia's Federal Security Service (FSB), active since at least 2004 with victims in over 50 countries.
-
Threat ActorSandworm Team
Destructive threat group attributed by MITRE ATT&CK to Russia's GRU military unit 74455, active since at least 2009 and linked to Ukrainian power-grid attacks and the 2017 NotPetya worm.