Russian Cyberwarfare Capabilities: Intelligence, Disruption and War

An evidence-led journey through Russia’s cyberwarfare system—from the Ukrainian power-grid attacks and NotPetya to SolarWinds, wartime wipers, logistics espionage, edge-device compromise, proxies, and the defensive lessons of 2026.

Begin in western Ukraine, 23 December 2015: the screen moves by itself

Evidence cutoff: 18 September 2026. Late on a winter afternoon, operators at Ukrainian electricity distribution companies watched cursors move across their control screens. Someone using legitimate remote access opened breakers at substations. Call centers were flooded while customers tried to report that their lights had gone out. Destructive activity then made parts of the operators’ own environment harder to recover. Roughly 225,000 customers lost electricity for periods measured in hours, not days, and staff restored service by operating equipment manually.

The event matters because it turns an abstract phrase—state cyber capability—into a sequence of operational achievements. The intruders had to enter enterprise systems, obtain credentials, learn the distribution environment, cross organizational boundaries, understand operator workflows, coordinate actions at several utilities, interfere with response, and still choose a moment when the social effect would be visible. Malware was present, but malware was not the whole operation. Knowledge, access, timing, target engineering, and practiced human action produced the outage.

CISA’s 2015 Ukraine grid record links the campaign to Russian state-sponsored actors and records the use of BlackEnergy for credential theft and KillDisk for destructive effect. The following year, a purpose-built capability commonly called Industroyer or CrashOverride disrupted transmission in Kyiv. These incidents established demonstrated—not hypothetical—capacity to reach from ordinary information technology into electricity operations.

They also establish the limits of dramatic language. The power system did not collapse nationally. Operators retained enough understanding and manual capability to restore service. The useful question is therefore not “Can Russia turn off a country?” It is: which actor can obtain access to which system, convert that access into a timed service effect, and sustain the effect against prepared defenders? The practical definition of cyberwarfare begins with objectives, authority, context, targets, and effects rather than the presence of malware alone.

This resource follows that chain from access to consequence. It uses government attributions, judicial records, victim and vendor reporting, and carefully labeled analysis. Public attribution is evidence of a government’s assessed judgment; an indictment contains allegations, not convictions; a vendor alias describes observed activity, not necessarily a fixed organization; and a hacktivist claim proves only that the claim was made. Those distinctions are essential to understanding Russian capability without turning a complex system into mythology.

The map behind the cursor: information confrontation and several state services

Russia does not organize cyber power as a single “cyber army.” The more useful map begins with missions. Russian military and security writing places technical operations within a broader contest over information: obtaining it, denying or corrupting it, protecting one’s own command and public narrative, and influencing how an adversary decides. A NATO Defense College handbook based largely on Russian sources describes this concept as information warfare or information confrontation and warns against reducing it to network intrusion. Technical access, electronic warfare, deception, media activity, psychological pressure, and conventional action may contribute to the same political purpose without being controlled by one operator.

Public attributions identify at least three major state institutions. The GRU, Russia’s military intelligence service, contains several units with different operational records. Unit 26165 is publicly associated with the activity cluster widely called APT28, Fancy Bear, Forest Blizzard, Sofacy, or Sednit. Its record includes intelligence collection, credential theft, targeting of political and military organizations, and hack-and-leak operations. Unit 74455—the Main Center for Special Technologies—is publicly associated with Sandworm and destructive campaigns. Unit 29155, already known for clandestine physical activity, was publicly exposed in 2024 for a cyber campaign that included WhisperGate and operations intended for espionage, sabotage, and reputational harm.

The FSB, Russia’s security and counterintelligence service, conducts its own cyber operations. In 2023, the United States disrupted the Snake peer-to-peer malware network and attributed it to a unit in FSB Center 16. The Snake disruption record says the unit tracked as Turla had used Snake for nearly two decades against governments, journalists, and other targets in at least 50 countries. Center 16 also contains other activity; “Turla” should not be treated as a label for everything the center does.

The SVR, Russia’s foreign intelligence service, favors patient strategic collection. United States and allied agencies associate it with APT29, Cozy Bear, Nobelium, and other vendor names. The SVR attribution record attributes the SolarWinds supply-chain compromise to the service. The operation’s value was not destruction but privileged access to selected government and corporate networks at scale, followed by careful exploitation of the most valuable victims.

Alias discipline prevents analytical error. “APT28” is a research construct assembled from overlapping observations; Unit 26165 is a Russian military designation. Their overlap can be strongly assessed without assuming that every vendor’s APT28-tagged event was performed by the same crew, under the same command, for the same purpose. Likewise, Sandworm, Turla, and APT29 are useful handles, not official membership lists. A sound cyber attribution product records the issuing authority, confidence language, evidence type, competing explanations, and the exact scope of the claim.

From espionage to spectacle: APT28, Sandworm and the value of stolen truth

The difference between collection and effect becomes visible in two GRU records. Unit 26165 has repeatedly pursued information that becomes valuable twice: first as intelligence, then as material that can be selectively disclosed. United States prosecutors alleged that Unit 26165 officers penetrated anti-doping organizations and stole medical information, while infrastructure operated by Unit 74455 released selected material through the “Fancy Bears’ Hack Team” persona and cultivated journalists. The operation combined authentic theft, selective presentation, false provenance, and amplification. A document can be genuine while the surrounding narrative remains manipulative.

The 2016 interference campaign against the United States followed a related logic: penetrate political organizations, steal internal material, release it through fronts, and exploit the news cycle. The cyber component created access; the information component converted access into political attention. That is why cyber-enabled influence operations cannot be handled as ordinary breach notification. Defenders must authenticate the corpus, warn that omissions or alterations may change meaning, protect affected people, coordinate legal and communications teams, and avoid letting the adversary dictate the publication calendar.

Unit 74455’s public record demonstrates a different emphasis. The United States Unit 74455 indictment alleges responsibility for the 2015 and 2016 Ukrainian electricity attacks, NotPetya, Olympic Destroyer, attacks against investigations into the Salisbury nerve-agent poisoning, and disruptive operations against Georgia. The defendants are presumed innocent unless proven guilty, but the indictment and allied attributions form a detailed public account of the government’s assessment.

NotPetya is the pivotal case. In June 2017, malicious code spread through the update mechanism of M.E.Doc, accounting software widely used in Ukraine. It presented a ransom demand but was engineered for destruction, not reliable recovery. Worm-like propagation carried it through interconnected enterprises and across borders. Shipping, pharmaceuticals, logistics, manufacturing, and public services experienced severe disruption; global losses ran into billions. A campaign aimed at Ukraine produced indiscriminate consequences because business trust, software distribution, identity, and network connectivity crossed national boundaries.

Olympic Destroyer then added deception. The malware used during the 2018 Winter Olympics incorporated artifacts that pointed toward other actors, complicating early attribution. The lesson is not that attribution is impossible. It is that code similarity, language settings, and planted indicators are fragile evidence unless combined with infrastructure, operational behavior, victimology, human intelligence, judicial material, and state disclosures. Russia’s strength has often been the ability to combine a technically sufficient operation with ambiguity and a public story—not a need for flawless, exotic malware in every campaign.

The quiet counterpart: SolarWinds, cloud identity and patient access

In 2020, defenders discovered that signed updates for SolarWinds Orion had carried malicious code into thousands of customer environments. The access opportunity was enormous, but the operators did not treat every installation as an equal target. They selected a smaller set for follow-on activity, moved toward identity systems and cloud mail, and worked to preserve access while limiting discovery. The United States attributed the supply-chain operation to the SVR.

SolarWinds corrects a common bias in cyberwarfare analysis: the loudest operation is not necessarily the most strategically valuable. A foreign intelligence service may prefer months of access to diplomatic correspondence, policy deliberations, security architecture, source code, and trusted relationships over a visible outage. Destruction announces itself and prompts rebuilding. Espionage can quietly shape negotiation, technology acquisition, targeting, and anticipation of an adversary’s decisions.

It also explains the move from endpoint malware toward identity. Once an actor can compromise federation, steal session material, create or abuse application credentials, or control a privileged cloud account, reinstalling a laptop may not remove access. CISA’s remediation guidance for SolarWinds described movement from on-premises networks into Microsoft cloud environments through compromised federated identity. Later advisories documented SVR interest in internet-facing services, technology providers, and cloud resources. The defensive unit is no longer “the infected machine”; it is the complete trust system spanning identity providers, synchronization, applications, service principals, recovery methods, logs, and administrators.

Russian operators also use ordinary administration capabilities. PowerShell, command shells, remote services, scheduled tasks, mailbox permissions, and valid accounts are valuable precisely because organizations use them every day. “Living off the land” does not make activity invisible, but it moves detection away from file names toward context: who executed the action, from which device and network, under which authentication path, against what asset, and whether the sequence matches a legitimate workflow.

This is a form of cyber pre-positioning: access may support collection today, a disruptive option tomorrow, or neither if it is discovered and removed. Analysts should not infer an order to attack from mere presence. Leaders should nevertheless treat privileged access to identity, management, backup, communications, and operational gateways as latent strategic risk. Eviction must rotate credentials and trust material, review cloud persistence, rebuild compromised authorities where necessary, validate logs from independent sources, and confirm that recovery accounts were not inherited by the intruder.

February 2022: cyber operations enter a full-scale invasion

Before Russian forces crossed the border, Ukrainian government and private networks were already under pressure. WhisperGate appeared in January 2022 disguised as ransomware but designed to destroy. Defacements paired disruption with threatening messages. On 23 February, destructive malware struck Ukrainian government, IT, energy, and financial organizations. One hour before the invasion on 24 February, an operation against Viasat’s KA-SAT network disrupted satellite communications in Ukraine and created spillover elsewhere in Europe. The European Union’s KA-SAT attribution assigns the activity to the Russian Federation and states that it facilitated the aggression.

The campaign continued with multiple wiper families and attempts against communications, government, energy, transport, and other critical sectors. In April, Ukrainian defenders and partners interrupted an operation using Industroyer2 against an energy provider. Russian actors also pursued military and political intelligence, compromised devices used by Ukrainian personnel, and sought access through providers and partners. Some cyber activity coincided in time, place, or sector with missile and ground operations.

Coordination must be described carefully. Microsoft reported destructive and espionage operations occurring alongside kinetic attacks but explicitly noted that public evidence did not always show whether cyber operators and physical forces coordinated directly or independently pursued common priorities. Temporal correlation is important; it is not a command order. A rigorous cyber effects assessment separates technical effect, service degradation, operational consequence, human impact, and strategic result.

The anticipated digital knockout did not occur. Ukraine had years of hostile experience, capable incident responders, international intelligence sharing, private-sector support, distributed communications, manual workarounds, and rapid migration of data and services to infrastructure outside the immediate battlespace. Many wipers damaged systems, yet effects were often localized or recoverable. Russia still gained intelligence and imposed costs, but cyber operations did not substitute for the logistics, mass, firepower, occupation, and political legitimacy required to achieve the invasion’s objectives.

That outcome is not proof that cyber operations were unimportant. Communications outages, lost records, disrupted municipal systems, unsafe industrial conditions, and uncertainty can burden civilians and defenders even when the national strategy fails. Satellite or cloud services can support military and civilian users simultaneously; electricity and telecommunications failures cascade into healthcare, water, finance, and family contact. Assessing civilian harm and reverberating effects requires tracing dependencies and duration, not simply labeling the initial target “military” or “critical infrastructure.”

After the opening shock: logistics, cameras, cloud accounts and routers

As the war continued, the most revealing targets were often not front-line weapons. They were the systems that made support visible: transport coordinators, ports, airports, maritime organizations, IT providers, defense suppliers, and cameras near crossings and military installations. A coalition of agencies reported in the 2025 logistics advisory that GRU Unit 26165 had targeted Western logistics and technology organizations since 2022. Observed techniques included credential guessing, spear-phishing, exploitation of Microsoft Exchange mailbox permissions, and access to internet-connected cameras near Ukrainian borders and military facilities.

This is battlefield support through the digital rear. A compromised mailbox can reveal schedules, cargo descriptions, contacts, routing changes, and incident reports. A camera can reveal traffic patterns or confirm that equipment passed a location. An IT provider may offer access to several downstream organizations. None of these systems needs to be destroyed to create military value. The collection requirement—understand the flow of aid—determines the target.

The same logic reaches small office and home routers. In April 2026, the United Kingdom’s NCSC published a 2026 router advisory assessing APT28 as almost certainly GRU Unit 26165. It reported activity from 2024 into 2026 in which vulnerable routers were altered to direct DNS queries toward actor-controlled systems, enabling adversary-in-the-middle attempts to harvest passwords and OAuth or similar tokens. The NCSC assessed the activity as broad and opportunistic at first, with likely filtering for people of intelligence value.

The sequence explains the contemporary playbook. Scan or acquire exposed infrastructure; exploit a known weakness or weak administration; redirect or observe legitimate traffic; capture authentication material; select valuable identities; and operate through ordinary web, email, or cloud services. The edge device becomes both collection point and camouflage. Defenders who monitor only endpoints may never see the first manipulation.

By 2026, allied governments also publicly attributed FSB Center 16 activity against critical infrastructure, including a December 2025 attempt against Poland’s energy grid, and warned about persistent exploitation of weakly managed routers. These public findings broaden the current picture beyond the familiar APT28–Sandworm pair. Russia retains destructive capabilities, but sustained access, intelligence preparation, surveillance, and sabotage options against Ukraine’s supporters may provide more repeatable value than another globally conspicuous worm.

The defensive response begins by identifying cyber key terrain: identity providers, email, logistics data, external connectivity, cameras, remote administration, software suppliers, backups, and OT gateways whose compromise would expose or interrupt the mission. Inventory internet-facing devices; remove management interfaces from public access; replace unsupported routers; enforce phishing-resistant authentication; restrict mailbox and application consent; monitor DNS and configuration changes; retain identity and cloud audit logs; and test recovery without the primary directory or network-management plane.

The gray outer ring: criminals, hacktivists, companies and deniable personas

Russia’s wider ecosystem gives the state reach and ambiguity, but “proxy” is not a universal explanation. Four relationships should be kept separate. Directed actors act under instructions or control. Enabled actors receive infrastructure, access, money, protection, or other support. Tolerated actors operate because authorities choose not to suppress them, sometimes in exchange for observing informal boundaries. Aligned actors independently pursue a compatible cause. One group can move among these categories over time, and public evidence may establish only part of the relationship.

Evil Corp provides an unusually specific case. The United Kingdom National Crime Agency’s Evil Corp assessment states that, before 2019, Russian intelligence services tasked the cybercriminal group to conduct cyberattacks and espionage against NATO allies. It describes leader Maksim Yakubets as the principal contact with officials and details family and institutional relationships that helped protect the group. That finding supports a state–criminal connection for this actor and period; it does not prove that every Russian-speaking ransomware crew receives state orders.

Hacktivist branding creates a different problem. Groups such as KillNet and NoName057(16) have claimed DDoS attacks against governments, banks, transport, media, and other organizations supporting Ukraine. Availability attacks can interrupt public access and create headlines, but claims often exaggerate duration, uniqueness, or operational consequence. In July 2025, Europol-supported Operation Eastwood targeted infrastructure and participants associated with NoName057(16), treating it as a pro-Russian cybercrime network. Law-enforcement characterization is stronger than social-media self-description, yet it still does not by itself establish a Kremlin command chain.

The public record became more explicit in July 2026. The European Union’s EU ecosystem statement described Russian use of an ecosystem spanning intelligence services, cybercriminal groups, self-proclaimed hacktivists, private companies, and enabling infrastructure. It imposed restrictive measures on selected individuals and entities and distinguished actors operating under instruction, direction, or control from the wider environment. Sanction designation is an official policy and attribution action; analysts should record its legal basis and claims rather than treating it as raw forensic evidence.

Plausible deniability is therefore an effect of organizational distance and evidentiary difficulty, not a magic property that erases responsibility. A persona can front a state operation, amplify a genuine criminal breach, recycle leaked material, or claim an outage it did not cause. Assess each layer independently: incident reality, technical cluster, operator identity, support relationship, sponsor, direction or control, and state responsibility. Confidence can be high at one layer and low at the next.

What the capability means for defenders—and what it does not mean

Russia’s cyberwarfare capability is formidable because it is diverse. It can pursue strategic espionage without disruption, turn stolen information into influence, prepare access to infrastructure, damage data, interfere with industrial processes, observe logistics, compromise communications, and exploit a surrounding ecosystem. Different institutions can pursue several of these missions at once. That makes a single “Russian IOC list” a poor defensive strategy.

It is not omnipotent. Operations have been exposed, blocked, reversed, or constrained by poor execution, defender preparation, manual workarounds, segmentation, rapid information sharing, international disruption, and the difficulty of converting technical access into durable political effect. NotPetya’s uncontrolled spillover imposed enormous costs but also generated attribution and sanctions. Snake survived for years but was eventually disrupted. Wartime wipers damaged organizations without collapsing the Ukrainian state. Capability should be measured by repeatable mission outcomes, not by the theatricality of malware names or claims.

Build defense around five operational questions:

  1. What must keep working? Map critical services, people, suppliers, identities, data, communications, and physical dependencies. Define acceptable degradation and the point at which a technical event becomes a mission failure.
  2. Where can trust be converted into access? Examine software updates, federated identity, cloud applications, service accounts, remote management, email delegation, routers, cameras, and technology providers. These paths recur because they blend into legitimate administration.
  3. Can the organization see and evict an identity-level intruder? Preserve independent identity, cloud, DNS, network, endpoint, and administrator telemetry. Rehearse federation compromise, token revocation, credential rotation, trusted-application review, and clean-room recovery.
  4. Can destructive or cyber-physical effects be contained? Separate business and operational networks, strictly mediate remote access, maintain offline or immutable recovery material, validate engineering logic, test manual operation, and make safety—not speed—the first constraint in OT response.
  5. Can leaders communicate through uncertainty? Predefine how legal, operational, intelligence, safety, and communications teams will distinguish confirmed effects, attribution assessments, adversary claims, and unresolved gaps.

Update the assessment by mission and evidence. Track which services and units are publicly linked to an operation, the confidence and source basis, the access vector, the target function, the observed effect, recovery time, spillover, and strategic consequence. Preserve negative evidence: systems targeted but not disrupted, attempted actions that failed, and services restored faster than expected. These observations prevent capability estimates from becoming a catalogue of attacker successes.

For a current secondary synthesis, the LRQA 2026 report surveys APT28, Sandworm, logistics surveillance, sabotage, critical infrastructure, and influence. Use it as a guide to questions and technical references, then verify consequential judgments against the underlying government advisories, victim records, judicial documents, and telemetry. That habit—read broadly, source narrowly, preserve uncertainty—is the core discipline for following Russian cyber operations after this page’s evidence cutoff.

Frequently asked questions

What are Russia’s main cyberwarfare capabilities?

Public evidence shows capabilities for long-term espionage, credential and identity compromise, software-supply-chain intrusion, hack-and-leak influence, destructive malware, communications disruption, operational-technology attack, reconnaissance of logistics and military support, and the use of state-linked or state-tolerated non-state actors. Capability does not mean every operation succeeds or that every Russia-aligned claim is authentic.

Which Russian agencies conduct cyber operations?

Public government attributions identify multiple GRU units, the FSB, and the SVR. Unit 26165 is associated with APT28-style espionage and influence activity; Unit 74455 with Sandworm and destructive operations; Unit 29155 with sabotage-oriented activity including WhisperGate; FSB Center 16 with Turla and other operations; and the SVR with APT29 and the SolarWinds espionage campaign. These are mission-oriented descriptions, not a complete classified organization chart.

Are KillNet, NoName057(16), and Russian cybercriminals controlled by Moscow?

Not as a blanket proposition. Some non-state actors have documented relationships, tasking, links, or enabling roles; others are primarily ideological, criminal, opportunistic, or publicity-driven. Evidence must be assessed group by group and operation by operation. Alignment, tolerance, direction, and control are different relationships.

Did Russian cyber operations determine the outcome of the war in Ukraine?

No public evidence supports that conclusion. Cyber operations caused real espionage, disruption, destruction, and civilian risk, but Ukraine’s defenses, rapid remediation, cloud migration, private-sector support, redundant communications, and the limits of cyber effects prevented the anticipated strategic knockout. Cyber power has supported the war without replacing conventional force.

How should an organization defend against Russian state activity?

Start with mission dependencies rather than an actor-name checklist. Protect identity and recovery paths, remove exposed administration, replace unsupported edge devices, patch known exploited vulnerabilities, retain cloud and network telemetry, separate IT and OT, test manual operation and restoration, monitor trusted suppliers, and rehearse communications during destructive or identity-wide compromise.