Unit 26165 is a cyber operations unit of Russia’s military intelligence service, the GRU, responsible for the threat actor tracked as APT28. It conducts state-sponsored cyberespionage against government institutions, international organizations and civilian targets, including organizations involved in chemical-weapons verification, aviation-disaster investigations and sporting integrity. Its operations include deploying officers abroad to conduct close-access cyberattacks, including under diplomatic cover. Dutch authorities, working with the United Kingdom, disrupted a Unit 26165 operation against the Organisation for the Prohibition of Chemical Weapons in The Hague in April 2018. An officer involved also participated in operations targeting Malaysian institutions associated with the MH17 investigation, including the Attorney General’s office and Royal Malaysian Police. Related activity targeted officials attending a World Anti-Doping Agency conference in Switzerland. A Canadian Centre for Ethics in Sport official’s laptop was compromised with APT28 malware, followed by broader compromise of the organization’s systems; APT28 also compromised infrastructure belonging to the International Olympic Committee. Unit 26165 uses compromised network infrastructure to conceal malicious traffic. In February 2024, the FBI dismantled a botnet of compromised Ubiquiti EdgeOS routers operated by the unit to proxy malicious traffic against the United States and allied nations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Russia-linked operator of a botnet of compromised Ubiquiti Edge OS routers used to proxy malicious traffic.
Referenced as a named Russian threat actor/unit associated with high-end malware campaigns, but no further operational detail is provided in the content.
Named Russian military unit within the GRU, explicitly identified as responsible for APT28. Its officers conducted the disrupted close-access operation against the OPCW in The Hague. The content also connects these officers to operations targeting the MH17 investigation in Malaysia and a WADA conference in Switzerland, and to planned travel to the OPCW-designated laboratory in Spiez.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.