What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
U.S. adversaries’ use of cybercrime is not one kind of relationship. In cases documented by Google Threat Intelligence Group (GTIG), the U.S. Department of Justice (DOJ), and the FBI, state-linked operators have reused criminal tools or infrastructure, paid criminal specialists, engaged in activity that may support a state’s goals, and conducted financially motivated operations themselves. Shared malware or a criminal-looking attack does not, by itself, prove that a government directed the criminals behind it.
What “using cybercriminals” can mean
In its February 11, 2025 assessment, Cybercrime: A Multifaceted National Security Threat, GTIG describes several distinct ways state interests and cybercrime overlap. FBI Director Christopher Wray offered a similar three-part summary in prepared congressional testimony on July 24, 2024: “Some cybercriminals contract or sell services to nation-states; some nation-state actors moonlight as cybercriminals to fund personal activities; and some nation-states are increasingly using tools, such as ransomware, typically used by criminal actors.”
| Mechanism | What it means | What it does not establish on its own |
|---|---|---|
| Buying or reusing criminal tools and infrastructure | A state-linked operator uses malware, hosting, or a compromised network that is available in criminal markets or was built by criminals. | That the operator hired, directed, or even contacted the tool’s author. |
| Paying or contracting criminal specialists | A government or state-linked organization pays a criminal group to develop or provide a capability. | That every operation by the contractor serves the government, unless evidence supports that claim. |
| Criminal activity that supports state objectives | A financially motivated or dual-purpose actor conducts operations that may advance a state’s interests. | A formal command relationship, especially when the exact relationship is assessed as unclear. |
| State-linked operators seeking revenue | Operators associated with a government also pursue financially motivated crime. | That the financial activity was necessarily authorized by the state. |
The distinctions matter: malware is a capability, infrastructure is a resource, and personnel relationships are a separate question. A tool’s criminal origins can explain how an operation was equipped without resolving who ordered it or why.
Why Russian operations feature prominently
GTIG’s 2025 assessment says Russian groups increasingly used free or publicly available criminally used malware and tooling amid resource constraints and operational demands, particularly after Russia’s full-scale invasion of Ukraine. It also describes intelligence relationships with cybercriminal groups being used to advance national objectives. These are findings and assessments in a report published on February 11, 2025, not a live inventory showing that every cited campaign remains active today.
#1 Best Overall
APT44 used criminal-market tools and infrastructure
GTIG associates APT44, also known as Sandworm, with Russian military intelligence. It describes the group using criminally sourced tools and infrastructure as disposable capabilities that could be used on short notice. The report names DARKCRYSTALRAT (DCRAT), WARZONE, and RADTHIEF, and says APT44 used bulletproof hosting advertised in Russian-speaking criminal communities.
GTIG observed APT44 campaigns deploying RADTHIEF against victims in Ukraine and Poland in 2022 and 2023. In one campaign, the group spear-phished a Ukrainian drone manufacturer and used SMOKELOADER to load RADTHIEF. These examples show an operator drawing on tools and infrastructure associated with criminal markets; they do not, by themselves, show that the malware’s developers participated in the campaigns.
GTIG also reported that suspected Iranian group UNC5203 used RADTHIEF in May 2024 in an operation with themes associated with Israel’s nuclear research industry. This is a specific reported operation, not evidence that Iranian state-linked activity generally relies on criminal tooling.
GRU operators repurposed a criminally built router botnet
In a February 15, 2024 account, updated February 6, 2025, DOJ said non-GRU cybercriminals installed Moobot malware on Ubiquiti EdgeOS routers whose administrator passwords were still set to publicly known defaults. GRU Military Unit 26165—also known as APT28 and by other names—then used Moobot to install its own scripts and files, converting the botnet into a global cyber-espionage platform.
Free tools Windows power users keep installed
One-click scans. No signup required.
DOJ said a court-authorized operation in January 2024 neutralized a network of hundreds of routers and temporarily changed firewall rules to block remote management. The release separately quoted an FBI official referring to remediation of more than a thousand routers globally; that broader figure and DOJ’s description of the network of hundreds are different scopes and should not be treated as the same count.
GTIG assessed that some former CONTI members supported attacks on Ukraine
GTIG assessed that former CONTI members formed part of an initial-access-broker group conducting targeted attacks against Ukraine, tracked by CERT-UA as UAC-0098. CONTI publicly announced support for Russia after the invasion, but that history does not establish that the Russian government directed every later action by an individual former member.
Rank #3
China-related cases show different kinds of overlap
DOJ said the PRC government paid for a PlugX version
On January 14, 2025, DOJ and the FBI reported an operation against malware used by China-backed hackers. DOJ said court documents described the PRC government paying Mustang Panda, also known in private-sector reporting as Twill Typhoon, to develop a version of PlugX. The group used that version to infect, control, and steal information from computers.
According to DOJ, the campaign targeted U.S., European, and Asian government and business victims as well as Chinese dissident groups. A court-authorized operation deleted the malware from approximately 4,258 U.S.-based computers and networks. That number describes the U.S. portion of the operation, not the worldwide victim total; DOJ said the operation used nine warrants, with the last expiring January 3, 2025.
Ransomware-like behavior may have concealed espionage
GTIG says Chinese espionage operator UNC2286 carried out extortion-like activity, including use of STEAMTRAIN ransomware. The activity may have been intended to mask espionage, and the ransom note copied elements associated with DARKSIDE. GTIG explicitly said it had not established a connection between UNC2286 and the DARKSIDE ransomware-as-a-service operation. The resemblance is therefore not evidence that UNC2286 was a DARKSIDE affiliate.
Rank #4
APT41 has a history of espionage and financial crime
GTIG describes APT41 as a China-based operator it considers most likely a contractor for the Ministry of State Security. The group has a history of both espionage and financially motivated cybercrime, including activity targeting the video-game sector. “Most likely” is GTIG’s assessment, not an unqualified finding that applies to every operation attributed to APT41.
Iranian and North Korean activity also spans multiple motives
Beyond the suspected UNC5203 operation described above, GTIG reports Iranian groups conducting ransomware and hack-and-leak activity. It also describes North Korean state-linked actors generating revenue for the regime through cyber operations. These patterns widen the national-security concern beyond conventional espionage, but the report’s broad descriptions should not be read as proof that every criminal incident involving a particular tool or technique is state-directed.
Why criminal activity can become a national-security problem
GTIG argues that criminal ransomware and data theft can disrupt essential services, consume defenders’ time and capacity, and expose sensitive information that may be useful to other actors. The risk is therefore not limited to a government using a criminal group as a proxy: criminal operations can impose costs and create intelligence opportunities even when a direct state relationship is not established.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
Two figures in GTIG’s February 2025 report illustrate the scale of the issue within the sources it cites, but neither is a count of all cyberattacks worldwide:
- GTIG reported that Mandiant Consulting responded to almost four times more intrusions conducted by financially motivated actors than by state-backed actors in 2024. This is a comparison of intrusions Mandiant Consulting responded to, as reported by GTIG—not a census of global activity.
- GTIG said healthcare’s share of posts on the data-leak sites it tracked doubled over the preceding three years. That describes the report’s tracked-site observations, not every data theft or breach affecting healthcare.
How to judge claims about state–criminal links
When evaluating a report about a criminal group helping a government—or a state operator using criminal tools—look at the relationship claimed, the evidence behind it, and the confidence language. Government court-operation announcements, vendor threat-intelligence assessments, and public statements may describe different kinds of evidence; they are not interchangeable proof of every alleged underlying fact.
- Shared tool or infrastructure: establishes use or overlap, not necessarily a relationship with the people who created or operated it.
- Payment or contracting: is a stronger claim about a personnel or service relationship. In the PlugX case, DOJ said court documents described PRC government payment for development.
- Aligned activity or possible concealment: may support an assessment about purpose, but uncertainty should remain visible. GTIG said UNC2286’s ransomware-like behavior may have masked espionage while also saying no DARKSIDE connection was established.
- Dual motives: can coexist. GTIG describes CIGAR, tracked as UNC4895 and publicly reported as RomCom, as having both financial and espionage motives.
For CIGAR, GTIG says targeted intrusions against Ukrainian military and government entities date to late 2022 and assesses that the group expanded into espionage supporting Russian national interests after the full-scale invasion. It also says the precise nature of the group’s relationship with the Russian state is unclear. Calling the activity supportive of Russian interests should not be turned into a categorical claim that the state directed the group.
What the router case means for owners of affected devices
DOJ’s advice in the Moobot disruption was specific to affected routers and the weaknesses used in that case. It recommended factory-resetting affected devices, installing the latest firmware, changing default usernames and passwords, and using firewall rules to reduce unwanted exposure of remote management.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute- Factory-reset the affected router.
- Install its latest firmware.
- Change the default administrator username and password.
- Use firewall rules to limit unwanted access to remote-management services.
DOJ warned that resetting a router without changing the default administrator password could leave it open to reinfection. This case-specific guidance does not amount to an endorsement of any particular router or consumer product.
The central distinction
U.S. adversaries can gain cyber capabilities from criminal markets in several ways: by reusing tools and infrastructure, paying specialists, benefiting from criminal activity that aligns with state aims, or allowing state-linked operators to pursue revenue. The available examples establish some direct relationships and some operational overlaps, while leaving other relationships uncertain. Treating those categories separately is essential to understanding both the threat and what the evidence actually says.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

