Atlantic Council analyzes Russia's cyber ecosystem and Ukraine war
Policy analysis examining Russia's complex cyber actors, fragmented coordination, and limited wartime cyber impact against Ukraine—with recommendations for Western cyber threat assessment and defense.
The Atlantic Council's Eurasia Center publishes a strategic analysis of Russia's cyber operations during its invasion of Ukraine, challenging Western assumptions about Russian cyber dominance. The article documents that despite pre-invasion predictions of devastating cyber attacks on Ukrainian critical infrastructure, Russian cyber operations have been limited in destructive effect, marked instead by poor interagency coordination between the FSB, GRU, and SVR, inadequate integration with kinetic operations, and a focus on data theft and wiper malware over infrastructure disruption. The analysis attributes this gap between expectations and reality to multiple factors: weak military preparation, overestimated Russian capabilities, competition between security agencies, robust Ukrainian defenses, and misaligned strategic priorities. The piece emphasizes that Russia's cyber threat landscape is not a top-down command structure but a complex "nesting doll" of state agencies, patriotic hackers, state-recruited cybercriminals, private military companies, and criminal entrepreneurs operating with shifting relationships to the Kremlin. The author argues that understanding this ecosystem's permissiveness toward cybercrime, corruption, and competition is essential to realistic threat assessment. The article concludes with five policy recommendations: distinguish between cyber capabilities and execution; analyze the full Russian cyber ecosystem, not just state agencies; recognize that Russian cyber operations are inseparable from regime security; maintain intelligence sharing with allies; and invest in defensive and offensive cyber capabilities.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/content-series/russia-tomorrow/unpacking-russias-cyber-nesting-doll
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free