CyberWatchers
banner
cyberwatchers.bsky.social
CyberWatchers
@cyberwatchers.bsky.social
Interested in cyber security - highlighting news stories, advisories and cyber attacks.
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe.
www.bleepingcomputer.com/news/securit...
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Eu...
www.bleepingcomputer.com
July 13, 2026 at 12:45 PM
When Dutch security services detained four Russian intelligence officers in The Hague in 2018, they uncovered a rental car filled with burner phones and close-access hacking equipment.
smallwarsjournal.com/2026/04/15/g...
Operational Exposure in the Age of Attribution: GRU Lessons for Digital Force Protection
Explore GRU lessons for Digital Force Protection and how they shape the landscape of signature reduction in modern warfare.
smallwarsjournal.com
April 17, 2026 at 8:19 AM
Failed attempt by pro‑Russian cyber group to disrupt a thermal power plant in western Sweden.

Swedish Power Plant Targeted by pro-Russian Group in 2025, Government Says
www.globalbankingandfinance.com/swedish-powe...
Swedish Power Plant Targeted by Pro-Russian Cyber Group in 2025
A pro-Russian cyber group attempted to disrupt a Swedish power plant in 2025. The government notes a rise in Russian hybrid attacks on energy sectors.
www.globalbankingandfinance.com
April 15, 2026 at 12:04 PM
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
lab52.io/blog/drillap...
March 16, 2026 at 10:52 AM
Finland’s intelligence service warned that Russia and China continue to conduct extensive cyberespionage and influence operations targeting the country’s technology sector, research institutions and government.
supo.fi/en/overview-...
March 10, 2026 at 2:54 PM
Since April 2024, Sednit’s advanced development team has re-emerged with a modern toolkit centered on two paired implants, BeardShell and Covenant, each using a different cloud provider for resilience.

welivesecurity.com/en/eset-rese...
March 10, 2026 at 2:50 PM
Also known as APT28, Fancy Bear, and Forest Blizzard, the group has carried out credential-harvesting and espionage operations for more than a decade.
www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 8, 2026 at 2:44 PM
Russian state-backed hackers have run a months-long phishing campaign against users of UKR.NET, a popular Ukrainian webmail and news service, in an effort to harvest credentials and gather intelligence
therecord.media/russian-blue...
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users
Researchers said the campaign likely aimed to collect sensitive information from Ukrainian users in support of broader Russian intelligence objectives.
therecord.media
December 18, 2025 at 1:34 PM
Amazon Threat Intelligence observed sustained targeting of global infrastructure between 2021-2025, with particular focus on the energy sector. The campaign demonstrates a clear evolution in tactics.
aws.amazon.com/blogs/securi...
Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure | Amazon Web Services
As we conclude 2025, Amazon Threat Intelligence is sharing insights about a years-long Russian state-sponsored campaign that represents a significant evolution in critical infrastructure targeting: a ...
aws.amazon.com
December 18, 2025 at 1:03 PM
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
"...among the increasing number of groups, some appear to have associations with the Russian state through direct or indirect support."
www.cyber.gov.au/about-us/vie...
www.cyber.gov.au
December 10, 2025 at 9:53 AM
According to the indictment, CARR, also known as Z-Pentest, was founded, funded, and directed by the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).
www.justice.gov/opa/pr/justi...
Justice Department Announces Actions to Combat Two Russian State-Sponsored Cyber Criminal Hacking Groups
The Justice Department announced two indictments in the Central District of California charging Ukrainian national Victoria Eduardovna Dubranova, 33, also known as Vika, Tory, and SovaSonya, for her r...
www.justice.gov
December 10, 2025 at 9:30 AM
Russia is using Ukrainian digital resources it had stolen during the occupation of part of Ukrainian territories for its cyberattacks and disinformation operations
www.ukrinform.net/rubric-ato/4...
Weaponization of stolen IP addresses -- how Russia is exploiting Ukrainian digital resource in its war against Ukraine
RIPE NCC continues to serve occupying administration entities contrary to EU sanctions — Ukrinform.
www.ukrinform.net
December 4, 2025 at 2:34 PM
Based on evidence uncovered during the course of this investigation, Arctic Wolf Labs assesses with a medium-to-high confidence level that Russia’s GRU unit 29155 is utilizing SocGholish to target victims.
arcticwolf.com/resources/bl...
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine - Arctic Wolf
Arctic Wolf Labs recently identified a U.S.-based company that was targeted by the Russian-aligned threat group RomCom via SocGholish, operated by TA569. This is the first time that a RomCom payload h...
arcticwolf.com
November 26, 2025 at 2:37 PM
SolarWinds this week announced patches for three critical vulnerabilities found in its Serv-U enterprise file transfer solution.
www.securityweek.com/solarwinds-p...
SolarWinds Patches Three Critical Serv-U Vulnerabilities
SolarWinds this week announced patches for three critical vulnerabilities found in its Serv-U enterprise file transfer solution.
www.securityweek.com
November 20, 2025 at 10:55 AM
According to the press release put out by Thailand’s Cyber Crime Investigation Bureau (CCIB), the man is a “world-class” hacker who had previously breached secure systems and carried out attacks on various government agencies.
theins.press/en/news/286815
“World-class” Russian hacker wanted by FBI and arrested in Thailand is likely GRU officer Aleksey Lukashev
On Nov. 12, Thai cyber police announced the arrest of a 35-year-old Russian citizen on the island of Phuket, adding that the unnamed suspect stands wanted in the United States on charges of hacking go...
theins.press
November 14, 2025 at 10:01 AM
Google said it had observed APT28, a Russia-linked group associated with the country’s GRU military intelligence agency, using PROMPTSTEAL in Ukraine. Google said those attacks were the first time it had seen malware querying an LLM in the wild.
anesthesiaexperts.com/ai-based-mal...
AI-based malware makes attacks stealthier and more adaptive - Anesthesia Experts
Author: Eric Geller Cybersecurity DIVE Dive Brief: Cyber threat actors have recently begun using AI to develop malware, in a dramatic evolution of the technology’s role in the hacking ecosystem, Googl...
anesthesiaexperts.com
November 13, 2025 at 9:59 AM
Cybersecurity researchers have disclosed details of a new Android remote access trojan (RAT) called Fantasy Hub that's sold on Russian-speaking Telegram channels under a Malware-as-a-Service (MaaS) model.
thehackernews.com/2025/11/andr...
Android Trojan 'Fantasy Hub' Malware Service Turns Telegram Into a Hub for Hackers
Fantasy Hub RAT sold via Telegram exploits Android SMS and banking systems amid rising MaaS threats.
thehackernews.com
November 12, 2025 at 9:15 AM
www.netcraft.com/blog/thousan...
A Russian-speaking threat actor operating an ongoing, mass phishing campaign targeting people who might be planning (or about to leave for) a vacation has registered more than 4,300 domain names used in the attacks since the beginning of the year.
Thousands of Fake Hotel Domains Used in Massive Phishing Campaign
A Russian-speaking threat actor has registered 4,300+ domains in a sophisticated phishing campaign impersonating major travel brands like Airbnb and Booking.com to steal travelers’ payment data. Learn...
www.netcraft.com
November 12, 2025 at 8:38 AM
Victims included banks, telecommunications companies and engineering firms in Pennsylvania, California, Michigan, Illinois, Georgia and Ohio.
therecord.media/russian-hack...
Russian hacker to plead guilty to aiding Yanluowang ransomware group
Court documents show evidence proving Volkov served as an initial access broker for the ransomware gang — breaking into the network of victims and then offering his access for a percentage of the rans...
therecord.media
November 11, 2025 at 1:08 PM
Russian state-backed hacker group Sandworm has deployed multiple data-wiping malware families in attacks targeting Ukraine's education, government, and the grain sector, the country's main revenue source.
www.bleepingcomputer.com/news/securit...
Sandworm hackers use data wipers to disrupt Ukraine's grain sector
Russian state-backed hacker group Sandworm has deployed multiple data-wiping malware families in attacks targeting Ukraine's education, government, and the grain sector, the country's main revenue sou...
www.bleepingcomputer.com
November 6, 2025 at 2:07 PM
Silent Push Threat Analysts have uncovered threat actors using AdaptixC2 and has observed heavy ties linking AdaptixC2 to Russia and the Russian criminal underworld.
www.silentpush.com/blog/adaptix...
Silent Push Unearths AdaptixC2's Ties to Russian Criminal Underworld, Tracks Threat Actors Harnessing Open-Source Tool for Malicious Payloads
Silent Push has uncovered threat actors tied to the Russian underworld using the AdaptixC2 framework to deliver malicious payloads.
www.silentpush.com
October 30, 2025 at 11:10 AM
Attackers are gaining access using a custom, Sandworm-linked webshell. One of the webshells used was Localolive which, according to Microsoft, is associated with a sub-group of the Russian Sandworm group.
www.security.com/threat-intel...
Ukrainian organizations still heavily targeted by Russian attacks
Attackers are gaining access using a custom, Sandworm-linked webshell and are making heavy use of Living-off-the-Land tactics to maintain persistent access.
www.security.com
October 29, 2025 at 12:28 PM
COLDRIVER, a Russian state-sponsored threat group known for targeting high profile individuals in NGOs, policy advisors and dissidents, shifted operations after the May 2025 public disclosure of its LOSTKEYS malware.

cloud.google.com/blog/topics/...
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog
Russia state-sponsored COLDRIVER started using new malware immediately following a May public disclosure of their activity.
cloud.google.com
October 29, 2025 at 7:42 AM
Continuous investigation on the Water Saci campaign reveals innovative email-based C&C system, multi-vector persistence, and real-time command capabilities that allow attackers to orchestrate coordinated botnet operations.
www.trendmicro.com/en_us/resear...
Active Water Saci Campaign Spreading Via WhatsApp Features Multi-Vector Persistence and Sophisticated C&C
Continuous investigation on the Water Saci campaign reveals innovative email-based C&C system, multi-vector persistence, and real-time command capabilities that allow attackers to orchestrate coordina...
www.trendmicro.com
October 28, 2025 at 1:52 PM