GRU Unit 26165 is a Russian military intelligence cyber unit widely associated with Fancy Bear and assessed to operate on behalf of the Russian state. The unit is known for both remote intrusion activity and distinctive close-access operations in which operators travel abroad with technical equipment to compromise nearby wireless networks and establish or maintain access when remote methods are insufficient. Public attributions have linked Unit 26165 to the disrupted 2018 operation against the Organisation for the Prohibition of Chemical Weapons in The Hague, as well as earlier anti-doping-related targeting in Brazil and Switzerland. It has also been linked to prominent remote intrusion campaigns including the 2016 Democratic National Committee compromise and operations against international sports and anti-doping organizations. Unit 26165 has targeted politically sensitive organizations and investigations viewed as harmful to Russian state interests, including bodies connected to chemical weapons attribution, anti-doping enforcement, and support to Ukraine. More recent attributed activity has focused on the European defense-industrial and logistics ecosystem supporting Ukraine, especially logistics and technology entities involved in transporting aid. In that context, the unit has reportedly sought shipment schedules, routes, manifests, cargo details, and related sender-recipient information, indicating an intelligence requirement tied to supply-chain monitoring and potential disruption. Its tradecraft includes reconnaissance, wireless interception, close-access intrusion, persistent access operations, and broader cyber espionage support. Reporting also indicates coordination between cyber operators and support personnel, with remote reconnaissance support from other members of the unit during some operations. The unit’s operational profile distinguishes it from other Russian military cyber elements by combining traditional remote hacking with overseas physical-proximity collection in support of espionage and state-directed strategic objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Use known vulnerabilities — CVE 2020-0688 and CVE 2020-17144 — to establish persistent access and escalate privileges, which means gaining administrative control of servers and systems.
Use known vulnerabilities — CVE 2020-0688 and CVE 2020-17144 — to establish persistent access and escalate privileges, which means gaining administrative control of servers and systems.
The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials
The actors have weaponized multiple CVEs, including: CVE-2023-38831 in WinRAR for remote code execution
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian military intelligence activity targeting Western logistics and technology companies involved in transporting aid to Ukraine, as part of a broader campaign combining cyber espionage, surveillance, sabotage, intimidation, and supply-chain targeting.
Russian military intelligence activity targeting the European defense support ecosystem for Ukraine, especially logistics and technology firms, to obtain shipment-related information and support broader disruption, intimidation, and supply-chain targeting.
Russian military intelligence cyber unit conducting both remote intrusions and close-access/on-site hacking operations, including attempted compromise of OPCW systems and operations against anti-doping organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.