Germany formally blamed Russia for the 2015 cyberattack on the Bundestag, identifying Russian national Dmitry Badin as a suspected operative of the GRU’s Unit 26165, also known as APT28 or Fancy Bear. Federal prosecutors obtained an international arrest warrant accusing him of intelligence activity and data espionage, while Berlin summoned the Russian ambassador and said it had hard evidence tying Moscow to the intrusion.
Investigators said the breach began with spearphishing emails disguised as United Nations messages about the Ukraine conflict, leading to malware infections inside the parliamentary network. The attackers allegedly escalated privileges, used tools including Mimikatz, and exfiltrated at least 16 GB of data, including large volumes of lawmakers’ emails, before the operation was stopped. Germany also pushed for EU-wide sanctions under the bloc’s cyber sanctions regime, making the case one of Europe’s most prominent state-linked cyber attribution actions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The European Union imposed sanctions on Russia's GRU and officers Dmitry Badin and Igor Kostyukov for their roles in the 2015 Bundestag hack. The measures included travel bans, asset freezes, and a prohibition on EU citizens and businesses conducting transactions with the sanctioned entities.
Germany's federal prosecutor obtained an international arrest warrant for Dmitrij Badin, accusing him of intelligence activity and data espionage in connection with the 2015 Bundestag hack. German investigators assessed him as a leading figure behind the operation and linked him to GRU unit 26165, also known as APT28 or Fancy Bear.
A Dutch counterintelligence operation targeting suspected GRU unit 26165 operatives attacking the OPCW produced seized laptops and phones that later provided valuable information to German investigators examining the Bundestag hack.
German responders stopped the Bundestag intrusion after attackers had moved laterally, harvested passwords with tools including Mimikatz, and exfiltrated at least 16 gigabytes of data. The stolen material included tens of thousands of parliamentarians' emails.
An IT security company warned Germany's domestic intelligence service about suspicious server communications involving Bundestag systems, after which the BfV informed the BSI. The BSI then sent a team to Berlin to support the Bundestag administration, and the parliament's entire IT system was temporarily shut down during the response.
German prosecutors allege Dmitrij Badin created malware identified as VSC.exe and deployed it minutes later during the Bundestag intrusion. Prosecutors say the malware was used to steal access credentials as the attackers escalated privileges inside the network.
The cyberattack on the German Bundestag began with spearphishing emails sent to multiple members, using fake United Nations-themed messages about the Ukraine conflict to deliver malware. The intrusion targeted the Bundestag network, which then had more than 5,600 computers and about 12,000 registered users.
Germany's foreign ministry summoned the Russian ambassador over the Bundestag cyberattack and said Berlin would push for EU-level sanctions against those responsible. Chancellor Angela Merkel told parliamentarians Germany had hard evidence that Russia was behind the attack and called it outrageous.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
tagesschau.de
Open sourcezdnet.com
Open sourcepolitico.eu
Open sourcesueddeutsche.de
Open sourcebellingcat.com
Open sourcesecureworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.