GRU is the Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation, Russia’s military intelligence service and a central state actor in Russian offensive cyber, sabotage, and information operations. In cybersecurity reporting it is widely associated with multiple operational units, most notably Unit 26165, Unit 74455, and Unit 54777, and is frequently linked with activity clusters such as APT28. GRU cyber operations have been publicly attributed by multiple governments in connection with election interference, cyber espionage, destructive malware deployment, disruptive attacks on critical infrastructure, anti-doping and sports-related intrusions, and broader influence operations. GRU has been accused of interfering in the 2016 U.S. presidential election through intrusions into political organizations and dissemination of stolen data. Public indictments and government attributions also connect GRU officers and units to attacks against the Democratic National Committee, French political targets, Georgian entities, the OPCW, WADA, USADA, the Canadian Centre for Ethics in Sport, and the Swedish Sports Confederation. In Ukraine, GRU has been tied to pre-invasion and wartime cyber operations including DDoS attacks against the banking sector, deployment of WhisperGate against government entities, the Viasat disruption, attempted attacks on electric utilities, and other destructive or disruptive activity targeting government and critical infrastructure. Operationally, GRU demonstrates capabilities spanning reconnaissance, initial access, credential theft, exfiltration, destructive and disruptive post-compromise actions, botnet operations, and influence activity. Reported tradecraft includes phishing, use of compromised edge devices and routers as proxy infrastructure, close-access wireless intrusion operations, website defacement, publication of stolen data, and malware operations designed either to destroy systems outright or to masquerade as ransomware for deception. GRU-linked operations have also used DDoS as a preparatory or coercive measure and have targeted telecommunications, transportation, energy, and other critical infrastructure sectors. Public reporting further describes GRU investment in integrated cyber, signals intelligence, electronic warfare, and psychological operations capabilities, including regional PSYOP structures and specialized units. Beyond cyber espionage, GRU has been implicated in covert action and sabotage activity, including the Salisbury Novichok poisoning case and broader Russian sabotage and influence efforts in Europe. Its cyber and information operations are generally assessed as serving Russian state strategic objectives, especially military advantage, coercion, retaliation, and intelligence collection. The dominant motivation is espionage in support of Russian state interests, though some operations have also been destructive or influence-oriented.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The NotPetya attacks began by targeting Ukrainian agencies, but it quickly spread through the use of the EternalBlue exploit, which was developed by the National Security Agency and used in the WannaCry ransomware attacks.
In its own advisory for the CVE-2023-50224 vulnerability, TP-Link said that many of its products are affected, but that all of them have reached end-of-life status, which means they are no longer supported by the company.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as conducting targeted violence and industrial sabotage in Europe, including the Salisbury poisoning and a broader Russian-directed arson/sabotage network using criminal proxies recruited via Telegram.
Used the Moobot botnet of compromised Ubiquiti Edge OS routers to proxy malicious traffic in cyberespionage operations.
Russian military intelligence is described as operating a regional psychological operations and information operations structure across military districts, including a unique PSYOP-capable unit, military unit 67606, in the Black Sea Fleet.
Russian military intelligence service identified as a principal espionage and hybrid cyber threat to Switzerland and as using Swiss-based infrastructure for operations abroad.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.