Russia GRU Unit 29155 Cyber Operations

Explore top LinkedIn content from expert professionals.

Summary

Russia’s GRU Unit 29155 is a specialized group within the country’s military intelligence agency, notorious for both physical and cyber operations—including sabotage, espionage, and disruptive cyberattacks. Their cyber operations often target critical infrastructure and government networks worldwide, using techniques like credential theft and destructive malware to advance Russian state interests.

  • Prioritize device security: Regularly update and replace vulnerable network devices, especially routers, to prevent unauthorized access from sophisticated cyber attackers.
  • Monitor for suspicious activity: Keep a close eye on changes in network settings and unexpected certificate warnings, treating these as urgent signs of possible compromise.
  • Strengthen authentication: Deploy phishing-resistant multi-factor authentication and enforce strict password policies to reduce the risk of credential harvesting by state-sponsored groups.
Summarized by AI based on LinkedIn member posts
  • View profile for Alexander Leslie

    National Security, Defense & Cyber Intelligence | Senior Advisor, Recorded Future | Government Affairs, Strategic Communications & Executive Engagement | Cybercrime, Espionage & Influence Operations

    12,702 followers

    🚨 🇷🇺 - New Recorded Future Insikt Group report! This research documents how the GRU-linked threat group #BlueDelta continues to refine credential-harvesting operations in ways that are strategically modest in appearance, but geopolitically consequential in effect. Please read and share with your networks! What stands out here is not technical novelty, but the alignment between tradecraft, targeting, and Russian intelligence priorities. BlueDelta’s focus on a narrow set of victims tied to Turkish energy and nuclear research, European policy institutions, and organizations in North Macedonia and Uzbekistan reflects a deliberate intelligence requirement rather than opportunistic access. These are not random credentials. They sit at the intersection of energy security, defense cooperation, regional diplomacy, and sanctions-relevant research — domains where marginal insights can materially shape state decision-making. In that sense, this activity reinforces how cyber-enabled intelligence collection increasingly serves as connective tissue between military planning, economic statecraft, and foreign policy. BlueDelta’s sustained abuse of legitimate infrastructure (e.g., free hosting, tunneling services, trusted PDF lures, and authentic redirections) also carries second-order implications. By normalizing the weaponization of widely used internet services, state-aligned actors raise the defensive cost for governments and research institutions while complicating attribution and response. This erodes the practical boundary between benign digital ecosystems and intelligence collection platforms, a dynamic that disproportionately affects smaller states and under-resourced institutions that sit on strategic fault lines. Russia’s continued investment in low-cost, high-yield credential access underscores a preference for persistence over spectacle. Rather than disruptive or destructive cyber operations, Moscow appears content to quietly map relationships, monitor policy debates, and gain early insight into emerging energy and security discussions. Over time, this kind of access can inform influence operations, diplomatic pressure, or military signaling long before any crisis becomes visible. Credential theft is a structural enabler of modern intelligence competition. Defending against it requires treating research institutions, think tanks, and sectoral experts as part of the national security perimeter, not adjacent to it.

  • View profile for Dr. Paul de Souza

    Founder & President at CSFI.US | Securing Critical Infrastructure through Cyber Threat Intelligence | National Security Advisor | University Professor

    52,743 followers

    🚨The FBI just published a multi-nation PSA on an active #GRU🇷🇺 cyber operation. If you manage infrastructure or remote workers, read this. ───────────────────────────── 𝗧𝗵𝗿𝗲𝗮𝘁 𝗔𝗰𝘁𝗼𝗿: APT28 / Fancy Bear / Forest Blizzard GRU 85th Main Special Service Center (85th GTsSS) 𝗔𝗰𝘁𝗶𝘃𝗲 𝗦𝗶𝗻𝗰𝗲: At least 2024 ───────────────────────────── 𝗧𝗧𝗣𝘀 — 𝗛𝗼𝘄 𝗧𝗵𝗲𝘆'𝗿𝗲 𝗗𝗼𝗶𝗻𝗴 𝗜𝘁 🔓 𝗜𝗻𝗶𝘁𝗶𝗮𝗹 𝗔𝗰𝗰𝗲𝘀𝘀 — Credential harvesting + exploitation of CVE-2023-50224 on TP-Link SOHO routers. These are unpatched, internet-exposed edge devices sitting in homes and small offices. ↪ 𝗣𝗶𝘃𝗼𝘁 — Actors modify DHCP/DNS settings on compromised routers to point all connected devices to actor-controlled DNS resolvers. No malware on the endpoint required. 🎯 𝗔𝗱𝘃𝗲𝗿𝘀𝗮𝗿𝘆-𝗶𝗻-𝘁𝗵𝗲-𝗠𝗶𝗱𝗱𝗹𝗲 (𝗔𝗶𝘁𝗠) — Fraudulent DNS responses redirect users to actor-controlled infrastructure for targeted services (e.g. Microsoft Outlook Web Access). Traffic is intercepted when users click through TLS certificate warnings. 📦 𝗖𝗼𝗹𝗹𝗲𝗰𝘁𝗶𝗼𝗻 — Passwords, session/auth tokens, emails, and browsing data content normally protected by SSL/TLS is exfiltrated in plaintext. 🎖 𝗧𝗮𝗿𝗴𝗲𝘁𝗶𝗻𝗴 — Initial compromise is broad and indiscriminate. GRU then filters victims, prioritizing military, government, and critical infrastructure personnel. ───────────────────────────── 𝗧𝗲𝗰𝗵𝗻𝗶𝗰𝗮𝗹 𝗗𝗲𝗳𝗲𝗻𝘀𝗲𝘀 → Patch or replace SOHO routers — CVE-2023-50224 is actively exploited. If the device is end-of-support, replace it. → Disable remote management interfaces exposed to the internet. → Rotate default credentials on all edge devices. Factory defaults are not acceptable. → Enforce strict certificate validation policies. Treat any TLS warning as a hard stop, not a prompt to click through. → Deploy DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) on endpoints so DNS queries are not silently redirectable by a rogue resolver. → Require VPN with MFA for all remote access to sensitive systems. A compromised home router should not be a path into your org. → Monitor for unexpected DHCP/DNS configuration changes on edge devices as an IOC. ───────────────────────────── The DOJ and FBI have already disrupted part of this network. That does not mean it's over. ⚠️ Full PSA: IC3 Alert I-260407-PSA | 07 April 2026 #CyberSecurity #ThreatIntelligence #APT28 #GRU #NetworkSecurity #InfoSec #DNS Cyber Security Forum Initiative #CSFI

  • View profile for Yusuf Purna

    Chief Cyber Risk Officer at MTI | Advancing Cybersecurity and AI Through Constant Learning

    6,533 followers

    🔍 𝐖𝐡𝐢𝐬𝐩𝐞𝐫𝐆𝐚𝐭𝐞 𝐚𝐧𝐝 𝐁𝐞𝐲𝐨𝐧𝐝: 𝐈𝐧𝐬𝐢𝐝𝐞 𝐆𝐑𝐔’𝐬 𝐆𝐥𝐨𝐛𝐚𝐥 𝐂𝐲𝐛𝐞𝐫 𝐖𝐚𝐫𝐟𝐚𝐫𝐞 🔍 The recent indictments of Russian military state actors highlight the scale and sophistication of Unit 29155, a GRU unit responsible for devastating cyberattacks on Ukraine and NATO allies. Known for the WhisperGate campaign, this group deployed data-wiping malware disguised as ransomware, crippling critical Ukrainian infrastructure just before the 2022 invasion. These coordinated attacks targeted essential systems, sowing chaos and disrupting vital sectors during a time of escalating conflict. ⚡ The WhisperGate attacks were part of a broader strategy by Unit 29155 to conduct sabotage, espionage, and widespread disruption across 26 NATO countries. Exploiting vulnerabilities in widely used software, the group used publicly available cyber tools to infiltrate critical systems. Their methods—such as leveraging CVE exploits and default IoT device credentials—underscore how small cybersecurity oversights can lead to catastrophic breaches. These incidents serve as a critical wake-up call: failure to maintain robust cyber defenses can have far-reaching geopolitical consequences. 🌍 As a cybersecurity professional, I believe this is a pivotal moment for global defense strategies. The WhisperGate operation underscores the urgent need for multi-layered security frameworks and proactive risk management. System updates, network segmentation, and phishing-resistant MFA must become standard practice. In the face of increasingly sophisticated state-sponsored attacks, stronger public-private partnerships, cross-border intelligence sharing, and a relentless focus on closing exploitable gaps are essential. The stakes are simply too high to ignore the lessons learned from WhisperGate. 🚨 💡 How is your organization preparing for the next wave of state-sponsored cyber threats? What challenges have you encountered in implementing proactive cybersecurity measures? https://lnkd.in/gTASWAdh #cyberthreats #criticalinfrastructuresecurity #stateactors #cybersecurity #cyberriskmanagement

  • View profile for Andy Greenberg

    Senior Writer at WIRED

    32,191 followers

    Intelligence agencies and the FBI, DOJ and CISA have revealed that unit 29155 of Russia’s GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. A broad group of Western government agencies from countries including the US, the UK, Ukraine, Australia, Canada, and five European countries on Thursday revealed that a hacker group that has launched multiple hacking operations targeting Ukraine, the US, and other countries in Europe, Asia, and Latin America is in fact part of the GRU's Unit 29155, the division of the spy agency known for its brazen acts of physical sabotage and politically motivated murder. That unit has been tied in the past, for instance, to the attempted poisoning of GRU defector Sergei Skripal with the Novichok nerve agent in the UK, which led to the death of two bystanders, as well as another assassination plot in Bulgaria, the explosion of an arms depot in the Czech Republic, and a failed coup attempt in Montenegro. Now that infamous section of the GRU appears to have developed its own active team of cyber warfare operators. Since 2022, GRU Unit 29155's more recently recruited hackers have taken the lead on cyber operations, including with the data-destroying wiper malware known as Whispergate, which hit at least two dozen Ukrainian organizations on the eve of Russia's February 2022 invasion, as well as the defacement of Ukrainian government websites and the theft and leak of information from them under a fake “hacktivist” persona known as Free Civilian. "Special forces don’t normally set up a cyber unit that mirrors their physical activities,” one official tells WIRED. “This is a heavily physical operating unit, tasked with the more gruesome acts that the GRU is involved. I find it very surprising that this unit that does very hands-on stuff is now doing cyber things from behind a keyboard.” https://lnkd.in/ehvpRzeJ

  • View profile for Bob Carver

    CEO Cybersecurity Boardroom ™ | CISSP, CISM, M.S. Top Cybersecurity Voice

    53,304 followers

    A Hacker Group Within Russia’s Notorious Sandworm Unit Is Breaching Western Networks A team Microsoft calls BadPilot is acting as Sandworm's “initial access operation,” the company says. And over the last year it's trained its sights on the US, the UK, Canada, and Australia Over the last decade, the Kremlin's most aggressive cyberwar unit, known as Sandworm, has focused its hacking campaigns on tormenting Ukraine, even more so since Russian president Vladimir Putin's full-scale invasion of Russia's neighbor. Now Microsoft is warning that a team within that notorious hacking group has shifted its targeting, indiscriminately working to breach networks worldwide—and, in the last year, has seemed to show a particular interest in networks in English-speaking Western countries. On Wednesday, Microsoft's threat intelligence team published new research into a group within Sandworm that the company’s analysts are calling BadPilot. Microsoft describes the team as an “initial access operation” focused on breaching and gaining a foothold in victim networks before handing off that access to other hackers within Sandworm’s larger organization, which security researchers have for years identified as a unit of Russia’s GRU military intelligence agency. After BadPilot's initial breaches, other Sandworm hackers have used its intrusions to move within victim networks and carry out effects such as stealing information or launching cyberattacks, Microsoft says. Microsoft didn't name any specific victims of BadPilot's intrusions, but broadly stated that the hacker group's targets have included “energy, oil and gas, telecommunications, shipping, arms manufacturing,” and “international governments.” On at least three occasions, Microsoft says, its operations have led to data-destroying cyberattacks carried out by Sandworm against Ukrainian targets. Microsoft warns that BadPilot has specifically exploited a vulnerability in the remote access tool Connectwise ScreenConnect and Fortinet FortiClient EMS, another application for centrally managing Fortinet's security software on PCs. After exploiting those vulnerabilities, Microsoft found that BadPilot typically installs software that gives it persistent access to a victim machine, often with legitimate remote access tools like Atera Agent or Splashtop Remote Services. In some cases, in a more unique twist, it also sets up a victim's computer to run as so-called onion service on the Tor anonymity network https://lnkd.in/gNKqqPP9 #cybersecurity #Russia #BadPilot #GRU #West #English #US #UK #Australia #Canada

  • View profile for Lukasz Olejnik, Ph.D, LL.M

    Independent security & Data Protection researcher and consultant

    6,957 followers

    Russian GRU cyber operatives are running a large-scale, targeted operations against Signal and WhatsApp users of government officials, military personnel and civil servants. The fake support message in the advisory tells victims, in capital letters: "DON'T TELL ANYONE THE CODE, NOT EVEN SIGNAL EMPLOYEES." That literal line is in the phishing message. AND IT WORKED. Attackers didn't need to break Signal. It just needed officials who trusted a a random chat message more than their own security training. Dutch intelligence services confirmed Dutch government employees were among the victims. The campaign exploits no technical vulnerabilities in either app. Instead, it uses the apps' own features against their users. Two methods. 1. A fake "Signal Security Support Chatbot" contacts the target, warns of suspicious activity and a possible data leak, then asks for the SMS verification code and Signal PIN. Hand those over and the attacker takes full ownership of the account, moves it to a number they control, and reads everything going forward. The victim can re-register using their old number and will see their local chat history intact - so they assume nothing happened. The advisory notes, with some understatement, that "this assumption could be incorrect." 2. A malicious QR code, dressed as a group invitation, silently links the attacker's device to the victim's account. The victim keeps full access and notices nothing. The attacker just reads along. What makes this operationally elegant is the irreversibility. Signal has no central management by design. This is for reasons of user privacy. There is no way to remotely deactivate a stolen account. Once gone, it is gone. GRU operatives just understood this. The advisory may also imply something governments rarely say. Signal was being used for communications viewed as sensitive. Its warning against sending classified information over consumer messaging apps may reflect concern that actual practice had drifted beyond formal policy.

  • View profile for Liubov Velychko

    Investigative Journalist | Researcher in Information Operations & FIMI | Speaker

    3,067 followers

    #Russia deliberately operates in a legal grey zone where cyberattacks are rarely treated as acts of aggression under international law unless they cause immediate physical destruction or casualties. As long as there are no visible victims, the response remains restrained. #Moscow understands this perfectly. And exploits it. At the Kyiv International Cyber Resilience Forum, Serhii Demediuk, Chairman of the Board at the Institute of Cyber Warfare Research, articulated something that should concern every cybersecurity professional and FIMI expert in the EU and the United States. Instead of a single spectacular strike, Russia applies what can be described as a “thousand cuts” strategy: persistent, accumulative, and often deniable cyber operations that gradually exhaust resilience, erode public trust, and test political red lines. #Europe has already experienced multiple examples of this approach. On the day of the full-scale invasion of Ukraine in February 2022, the KA-SAT/Viasat satellite network was disrupted in an attack publicly attributed to Russia and condemned by the #EU; the incident affected several EU member states and demonstrated how quickly civilian infrastructure can be collateral damage. In 2023, #Denmark’s energy sector reported coordinated intrusions affecting more than twenty energy companies, with investigations pointing to activity associated with the GRU-linked Sandworm group. In 2024, #Germany and #Czech Republic publicly attributed malicious cyber activities to APT28 (also linked to the Russian #GRU), warning that the same actor targeted government entities and critical infrastructure operators across Europe. What makes the current phase even more concerning is the evolution toward a “double strike” tactic. Cyber operations increasingly occur alongside synchronized information attacks. The technical disruption is paired with amplified narratives exaggerating scale and impact. This was designed to intimidate, create panic, and undermine confidence in institutions. Even when the technical damage is limited, the psychological and political effects can be far more significant. This fusion of #cyber operations and #information manipulation is not accidental; it is strategic. A more coordinated and assertive approach to attribution, consequences, and integrated cyber-information response is essential. Russia is not merely probing systems. It is probing resolve.

  • View profile for Andy Jenkinson - WHITETHORN SHIELD

    Fellow Cyber Theory Institute. Director Fintech (FITCA). NAMED AN EXPERT IN INTERNET ASSET & DNS VULNERABILITIES AND THREAT INTELLIGENCE. IF I REACH OUT TO YOU - CHANCES ARE YOU HAVE A PROBLEM...

    39,686 followers

    On February 24, 2022—one hour before Russian armour crossed into Ukraine—the Viasat KA-SAT satellite network was gutted. The attackers, almost certainly Russia's GRU (Sandworm), did not hack the sky. They hacked the ground. The entry point was a misconfigured Fortinet VPN appliance in Viasat's Turin-based ground station. Once inside, the attackers moved to an FTP server and staged AcidRain, a wiper malware designed to erase flash memory. But the operation's stealth depended entirely on DNS. The malware used DNS over HTTPS (DoH) to mask its command-and-control traffic, blending malicious queries with legitimate web traffic—a technique that made it invisible to traditional security monitoring. DNS was not the target; it was the camouflage as it often is. When the kill command arrived via DNS beaconing, AcidRain destroyed over 27,000 SurfBeam 2 modems. The collateral damage cascaded across Europe: 5,800 German wind turbines lost remote monitoring, and tens of thousands of residential broadband users in France, Italy, and Poland went dark. The lesson is brutal: DNS trust made the attack invisible. PDNS was useless and could not stop it because the domains were new and unknown. Mockapetris warned, 95% of attacks rely on DNS—not because DNS fails, but because it succeeds - unknowingly, uncontrolled, and unsecured.

  • View profile for Linda Restrepo

    Executive Technologist | AI & Cybersecurity Strategist | Federal Research Leader (DOE/DoD/CDC/DOT) | Editor-in-Chief, N360™ — Sovereign Intelligence & National Security Technologies

    14,296 followers

    Europe’s hybrid threat landscape is no longer theoretical—it’s measurable. Recent open-source intelligence confirms that: ✅ Undersea & Energy Infrastructure: The 2023 Balticconnector pipeline damage, followed by multiple undersea cable cuts in 2024, demonstrate deliberate pressure on Europe’s critical energy routes. ✅ Navigation Interference: Over 1,500 recorded GPS-jamming events across Nordic airspace since 2023 forced Finnair and other carriers to suspend regional flights; ICAO publicly condemned these activities in 2025. ✅ Information Operations: Coordinated disinformation spikes consistently follow kinetic or cyber incidents—mirroring the “multi-domain synchronization” pattern outlined by EU StratCom and NATO Hybrid COE. ✅ Weaponized Migration: Finland’s 2023–2024 border closures and Poland’s 2024 Belarus corridor incidents show continued use of migration flows for coercive leverage. ✅ Attribution: GRU Unit 74455 (Sandworm) and Unit 29155 remain linked to cyber-physical and sabotage operations across the continent, as corroborated by multiple national investigations. These facts align with Dr. Igor van Gemert’s core assessment: hybrid warfare has evolved into a persistent, below-threshold campaign designed to exploit Europe’s legal and procedural inertia. The data point to one urgent priority—a unified EU-NATO intelligence and resilience framework capable of rapid attribution, infrastructure hardening, and synchronized counter-narratives. Linda Restrepo, Editor in Chief Inner Sanctum Vector N360™ #HybridWarfare #CyberSecurity #CriticalInfrastructure #EuropeanSecurity #NATO #InformationOperations #NationalResilience

  • View profile for Darren Mott, FBI Special Agent (Ret.), "The CyBUr Guy"

    Co-founder/Director of Cyber Operations @ FiveEyesLtd | Cybersecurity Expert

    7,592 followers

    I spent over two decades years chasing threats most people never see coming. Russian state hackers just made your supply chain their playground. Amazon's threat intel team confirmed APT29, Russia's elite cyber unit, and more commonly known as COZY BEAR, has been weaponizing cloud infrastructure to target Western critical infrastructure for years. Not theoretical. Not someday. Right now. Here's what should be keeping Logistics decision makers up at night: They're using AWS, Azure, and Google Cloud as command-and-control hubs. Your logistics systems, vendor portals, and supply chain software all run on these platforms. The lesson? Nation-state actors don't care about your firewall. They're already inside the infrastructure you trust. Three actions for logistics leaders today: 1. Audit your cloud security posture across all providers 2. Implement zero-trust architecture for supply chain access 3. Train your team to recognize sophisticated phishing—APT29 is patient and convincing This isn't an IT problem. It's a business continuity crisis waiting to happen. When your distribution network goes dark because of a nation-state attack, your customers won't care about the technical details. They'll remember you weren't prepared. What's your organization doing to harden supply chain infrastructure against state-sponsored threats? https://lnkd.in/ec65efzP

Explore categories