VORANT. Threat Intelligence Sign in Get the full feed

Experts dissect Russia's cybercriminal proxy model

medium threat government-nationalfinancial-servicesenergydefensetelecommunications

Atlantic Council experts examine how Russia uses cybercriminal groups like Conti and Evil Corp as proxies for state cyber operations amid the Ukraine invasion.

This roundtable discussion features five cyber policy experts analyzing Russia's use of non-state actors—cybercriminal groups—as instruments of state cyber statecraft. Key examples cited include Conti's public pledge of allegiance to the Kremlin following the invasion of Ukraine, Evil Corp's leader Maksim Yakubets' ties to the FSB, and TrickBot operators' apparent targeting of US election infrastructure in 2020. Experts describe a spectrum of state-criminal cooperation ranging from ad hoc tasking to deep sponsorship, noting that Russia grants criminal groups a 'long leash' as long as they avoid targeting domestic organizations, providing plausible deniability while advancing Kremlin interests abroad.

The discussion also covers Belarus-linked group UNC1151, which Ukraine attributes to Belarusian intelligence and which allegedly defaced government websites and deployed wiper malware in January 2022, later linked to spear-phishing campaigns targeting European nations aiding Ukrainian refugees. Experts differ on the degree of Belarus-Russia cyber cooperation, with some seeing alignment given Lukashenko's dependence on Russian support, and others viewing Belarusian actors as more independent.

Panelists reflect on Russian state-sponsored groups including Sandworm (GRU), APT28 (GRU), and Turla (FSB), noting Sandworm's history with BlackEnergy and the 2015 Ukrainian power grid attack, as well as the 2017 NotPetya attack attributed to Russian military intelligence. Discussion of the current war notes that expected large-scale destructive cyberattacks did not materialize alongside the invasion, with observed activity limited to DDoS attacks, defacements, and wiper malware—assessed as relatively rudimentary compared to expectations, though the NCSC's disclosure of Sandworm's Cyclops Blink tool suggests more capable tooling exists in reserve.

Mentioned in this report

Threat actors APT28BuhTrapContiEvil CorpSandwormTurlaUNC1151
Malware BlackEnergyContiCyclops BlinkNotPetyaTrickBotVPNFilter

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-russias-cyber-statecraft

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free