What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Russian cyber espionage is not a single campaign or a single set of tactics. U.S. government advisories describe operations linked to different Russian services and military units: SVR actors targeting cloud accounts and other organizations for intelligence collection, and GRU units conducting campaigns that can include espionage, disruption, sabotage, and reputational harm. Their targets and methods overlap in places, but the advisories describe distinct operations that should not be collapsed into one profile.
Which Russian-linked actors do the advisories describe?
Attribution names vary by government agency and security vendor. An alias is a label used by a particular source; it does not establish that every incident assigned that label is connected to every other incident assigned to it. The following comparison reflects the specific advisories and campaigns described by the U.S. agencies, not a universal catalog of all Russian cyber activity.
| Actor or unit | Aliases in the cited advisory | Reported focus and activity |
|---|---|---|
| Russian Foreign Intelligence Service (SVR) cyber actors | APT29, Midnight Blizzard (formerly Nobelium), the Dukes, and Cozy Bear, according to the NSA’s October 10, 2024 summary | The NSA says these actors have consistently targeted U.S., European, and global entities in defense, technology, and finance since 2021. Their aims include foreign-intelligence collection and enabling future cyber operations. |
| GRU Unit 26165 | APT28, Fancy Bear, Forest Blizzard, and BlueDelta, according to the NSA’s May 21, 2025 summary | A campaign reported as active since at least February 2022 targeted Western government organizations, logistics and transportation services, and technology companies, including organizations assisting Ukraine. The advisory also connects targeting of internet-connected cameras in Ukraine and nearby countries to monitoring shipment movements. |
| GRU Unit 29155 | The September 5, 2024 advisory describes actors affiliated with GRU Unit 29155; no alias mapping is needed to distinguish this operation from Unit 26165. | U.S. agencies assess that operations since at least 2020 have involved espionage, sabotage, and reputational harm. The advisory describes destructive campaigns, infrastructure scanning, and data exfiltration, with a focus since early 2022 on disrupting aid to Ukraine. |
These labels and descriptions come from separate NSA and partner-agency summaries: “NSA Issues Updated Guidance on Russian SVR Cyber Operations” (October 10, 2024), “NSA and Others Publish Advisory Warning of Russian State-sponsored Cyber Campaign Targeting Western Logistics and Technology Entities” (May 21, 2025), and “NSA, FBI, CISA, and Allies Issue Advisory about Russian Military Cyber Actors” (September 5, 2024). The dates describe the agencies’ reporting and campaign timelines, not proof that every operation continued unchanged through the publication date.
How do the documented operations get access?
The techniques vary by campaign. Across the advisories, reported access routes include password spraying, brute force, spearphishing, exploitation of known vulnerabilities, abuse of trusted relationships or supply chains, and compromise of cloud accounts. A technique associated with one campaign should not automatically be attributed to every actor or operation.
SVR: cloud accounts and identity persistence
The NSA’s February 26, 2024 cloud advisory summary says SVR actors commonly accessed cloud systems by logging into automated system accounts and inactive accounts using password spraying or brute force. These accounts may have weak passwords or no multifactor authentication. After gaining access, actors used system-issued tokens or registered devices to maintain it, while residential proxy services could make suspicious sign-ins harder to distinguish from ordinary activity.
#1 Best Overall
The October 10, 2024 SVR summary describes a wider set of methods: spearphishing, password spraying, exploitation of software vulnerabilities at scale, supply-chain and trusted-relationship abuse, custom malware, cloud exploitation, and living-off-the-land techniques. Living off the land means using legitimate tools or features already present in a victim environment, which can make malicious activity resemble routine administration. The advisory also describes privilege escalation, lateral movement, persistence in networks and cloud environments, and information exfiltration. Tor, leased infrastructure, compromised systems, and proxies can conceal activity.
GRU Unit 26165: credential attacks and vulnerable devices
For the campaign detailed in the May 21, 2025 advisory, the NSA reports password spraying, spearphishing, changes to Microsoft Exchange mailbox permissions, and exploitation of vulnerable small-office/home-office (SOHO) devices. It also reports targeting of internet-connected cameras in Ukraine and nearby countries to monitor shipment movements. These are reported methods and targets for that campaign, not a complete profile of Unit 26165 or all GRU activity.
GRU Unit 29155: espionage alongside disruption
The September 5, 2024 advisory describes destructive malware deployment, infrastructure scanning, and data exfiltration. It places those activities within a broader set of objectives that includes espionage, sabotage, and reputational harm. In other words, a campaign involving information collection may also aim to damage systems or disrupt support for Ukraine.
Who and what have been targeted?
The reported target set spans more than government networks. The February 2024 cloud advisory identifies government, think tank, healthcare, and energy targets, and says targeting expanded to aviation, education, law enforcement, local and state government, government financial departments, and military organizations. The October 2024 SVR summary highlights defense, technology, and finance entities in the United States, Europe, and globally. The May 2025 Unit 26165 summary adds Western government organizations, logistics and transportation services, and technology companies assisting Ukraine.
Rank #3
These sector lists are not interchangeable or exhaustive. They reflect what each advisory says about the activity it covers; they do not mean every named organization was compromised, or that every operation targeted all listed sectors.
What should organizations do to reduce risk?
The joint advisories emphasize identity security, timely remediation, visibility, and limiting how far an intruder can move. These are official recommendations, not guarantees that any one control will prevent compromise.
Rank #4
Secure accounts, tokens, and devices
- Review automated, inactive, and other system accounts. Disable accounts that are no longer needed, apply strong unique passwords, and require multifactor authentication where supported.
- Use phishing-resistant multifactor authentication for externally facing accounts, especially webmail, VPN, and accounts that can reach critical systems, as recommended in the September 2024 Unit 29155 advisory.
- Apply conditional-access policies and enroll authorized devices. Set short token validity periods where appropriate, and review how tokens and registered devices are issued, retained, and revoked.
- Audit account permissions, including Microsoft Exchange mailbox permissions, and investigate unexpected changes.
Patch exposed systems and establish a device baseline
- Prioritize patches and keep software current. The October 2024 SVR guidance specifically recommends reviewing security controls and baselining authorized devices, then scrutinizing systems that do not match the baseline.
- Remediate known exploited vulnerabilities and update internet-facing services and network equipment. The Unit 29155 advisory calls for routine updates and remediation of known exploited vulnerabilities.
- Inventory SOHO and other network devices that connect to organizational systems. Replace or isolate devices that cannot be updated or securely managed.
Limit movement and improve detection
- Segment networks so that an account or device compromise does not automatically provide access to critical systems.
- Monitor cloud sign-ins and changes to accounts, permissions, tokens, and device registrations. Investigate unexpected access involving inactive or automated accounts.
- Increase monitoring and threat hunting for the tactics and indicators identified in the Unit 26165 advisory. Consult the current full advisory and related vulnerability guidance for implementation details and updated indicators.
The advisories provide recommendations at a high level; the appropriate configuration depends on an organization’s systems and exposure. A control’s presence alone is not evidence that it is working: defenders need to verify enforcement, monitor exceptions, and investigate anomalies.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →How to interpret attribution and campaign timelines
Attribution statements should be read with their source and date attached. The NSA and partner agencies identify the actors and activity described in their advisories; private security firms may use different names or draw boundaries differently. Those differences do not by themselves prove that the groups are unrelated, nor do shared aliases prove that two reported incidents form one campaign.
Best Value
Likewise, “since at least” gives a lower bound for the activity described by an agency, not a precise start date or a continuous-operation claim. The Unit 29155 advisory uses that qualifier for operations since at least 2020; the Unit 26165 advisory uses it for the campaign since at least February 2022. Keep each timeline tied to its own unit and report rather than combining them into a single measure of Russian cyber activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

