The GRU, also known as Russia’s Main Intelligence Directorate, is the Russian military intelligence service responsible for state-directed cyberespionage, disruptive and destructive cyber operations, and information operations supporting Russian strategic interests. Its targets include government institutions, political organizations, critical infrastructure, international organizations, and sports and anti-doping bodies. It conducts both remote intrusions and close-access operations, including deploying officers abroad to attack wireless networks. Its principal publicly identified cyber units include Unit 26165, the 85th Main Special Service Center associated with APT28, and Unit 74455, the Main Center for Special Technologies associated with Sandworm. Unit 54777, the 72nd Special Service Center, conducts psychological and information operations in coordination with GRU cyber units. These groups and units are components of the broader service rather than interchangeable names for the entire organization. GRU operations have included the theft and release of Democratic Party information during the 2016 U.S. presidential election, intrusions against anti-doping organizations, and attempts to compromise the Organisation for the Prohibition of Chemical Weapons and institutions investigating the MH17 disaster. Its sports-related operations stole and published athletes’ medical records while posing as hacktivists to discredit Western athletes and sporting organizations. Its destructive activity includes NotPetya, WhisperGate attacks against Ukrainian government systems, and the February 2022 disruption of Viasat satellite communications. Unit 74455 also attempted to disrupt a Ukrainian electricity utility in April 2022. Operational techniques include spear phishing, impersonation, wireless-network compromise, data exfiltration, website defacement, distributed denial-of-service attacks, and destructive malware deployment. The GRU has used compromised routers and botnets, including Cyclops Blink and Moobot infrastructure, to maintain operational infrastructure and proxy malicious traffic. It has also used fraudulent DNS responses to facilitate adversary-in-the-middle attacks. Destructive malware masquerading as ransomware in its campaigns should not be equated with financially motivated ransomware or extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NotPetya attacks began by targeting Ukrainian agencies, but it quickly spread through the use of the EternalBlue exploit, which was developed by the National Security Agency and used in the WannaCry ransomware attacks.
In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical example of cyber collection supporting influence operations. Its theft and release of Democratic Party emails gained broader distribution through American news coverage. The article does not attribute the separately described contemporary Russia-linked malware operation to the GRU.
Described as conducting targeted violence and industrial sabotage in Europe, including the Salisbury poisoning and a broader Russian-directed arson/sabotage network using criminal proxies recruited via Telegram.
Used the Moobot botnet of compromised Ubiquiti Edge OS routers to proxy malicious traffic in cyberespionage operations.
Russian military intelligence is described as operating a regional psychological operations and information operations structure across military districts, including a unique PSYOP-capable unit, military unit 67606, in the Black Sea Fleet.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.