Unit 26165 is a Russian military intelligence threat actor associated with the GRU and widely tracked as a state-backed cyber espionage operator. The group has been linked to operations against the United States and allied nations and is known for conducting intrusive campaigns in support of Russian intelligence objectives. Reported activity includes operating botnet infrastructure built from compromised edge networking devices to proxy malicious traffic, enabling covert access and operational obfuscation during follow-on activity. Unit 26165 has also been associated with renewed high-end malware operations, indicating continued capability for sophisticated intrusion tradecraft. The actor’s observed behavior supports capabilities in initial access, persistence, defense evasion, reconnaissance, and post-exploitation. Its use of compromised network infrastructure for traffic relaying demonstrates an ability to build and maintain covert operational infrastructure at scale. As a GRU-linked actor, Unit 26165 is best characterized as a nation-state espionage threat rather than a financially motivated or ransomware-focused group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Russia-linked operator of a botnet of compromised Ubiquiti Edge OS routers used to proxy malicious traffic.
Referenced as a named Russian threat actor/unit associated with high-end malware campaigns, but no further operational detail is provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.