The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
GRU Unit 29155, also known as the 161st Specialist Training Centre, has been linked to covert physical operations and to cyber activity including espionage, data leaks and sabotage. The evidence comes from different sources: allied governments publicly attributed cyber operations to the unit, while earlier physical-operation links appear in a UK government profile and investigative reporting. A separate US indictment charges six people over alleged cyber activity; those charges are allegations, not findings of guilt.
What is GRU Unit 29155?
Unit 29155 is a Russian military intelligence unit also designated the GRU 161st Specialist Training Centre. A September 2024 statement by the UK National Cyber Security Centre (NCSC) said the unit had conducted malicious cyber activity since at least 2020. The NCSC described the activity as serving espionage, reputational harm through stolen and leaked information, and sabotage, including the destruction of data.
The unit’s reported activity spans distinct kinds of operations. Public accounts associate it with physical sabotage and attempted killings, while the allied cyber attribution covers computer-network operations. Those strands are connected to the same unit in official or investigative accounts, but they are not one case, and they do not all carry the same evidentiary status.
What cyber operations have been attributed to the unit?
WhisperGate attacks in Ukraine
The NCSC specifically attributed the deployment of WhisperGate against multiple victims in Ukraine before Russia’s 2022 invasion to Unit 29155. The US Department of Justice (DOJ), describing allegations in a criminal indictment, said WhisperGate was designed to destroy computers and data while appearing to be ransomware. The DOJ account says the malware was used against Ukrainian government systems, including systems with no military or defence role.
#1 Best Overall
The distinction matters: the NCSC publicly attributed the deployment to the unit, while the DOJ described the conduct alleged in its case. WhisperGate’s ransomware-like appearance was not proof that affected systems could recover their data by paying a ransom; the DOJ said the malware was designed for destruction.
Espionage, information exposure and sabotage
Beyond WhisperGate, the NCSC characterized Unit 29155’s cyber activity as including espionage, the theft and leaking of information to damage reputations, website defacement, and destructive attacks on data. These categories describe different effects: espionage seeks access to information, leaks expose stolen material, defacement changes what a website displays, and destructive activity aims to damage or erase data.
What does the US case allege?
The DOJ says five Russian military officers assigned to Unit 29155 and a civilian, Amin Stigal, were charged in a US case. According to the indictment as summarized by the DOJ, the alleged activity included probing protected computer systems associated with 26 NATO countries from August 2021 onward, as well as later targeting of systems in the United States and 25 NATO countries supporting Ukraine.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
These are allegations in an indictment, not findings that the defendants committed the charged conduct. The DOJ page was updated on February 6, 2025, with details about the charges and alleged operations. The criminal case concerns cyber activity; it is not a prosecution of the earlier physical operations attributed or linked to Unit 29155.
How do the reported physical operations fit the timeline?
The UK government profile associates wider Unit 29155 operations with the 2014 explosions at an ammunition warehouse in Vrbětice, Czechia, and the attempted murder of Sergei and Yulia Skripal in Salisbury in 2018. Separately, Bellingcat’s investigative reporting links GRU officers it identified as Unit 29155 members to travel to Bulgaria around poisoning attempts targeting arms manufacturer Emilian Gebrev and others in 2015. The Bulgaria account is investigative reporting, not a court finding.
| Date | Reported operation or activity | Source and evidentiary status |
|---|---|---|
| 2014 | Explosions at the Vrbětice ammunition warehouse in Czechia | Associated with wider Unit 29155 operations in a UK government profile |
| 2015 | Poisoning attempts targeting Emilian Gebrev and others in Bulgaria | Bellingcat investigative reporting links identified GRU officers to the case; not a court finding |
| 2018 | Attempted murder of Sergei and Yulia Skripal in Salisbury | Associated with wider Unit 29155 operations in a UK government profile |
| At least 2020 | Cyber activity including espionage, information exposure and sabotage | NCSC public attribution, issued in September 2024 |
| Before Russia’s 2022 invasion of Ukraine | WhisperGate deployment against multiple Ukrainian victims | Specifically attributed to Unit 29155 by the NCSC; DOJ separately describes indictment allegations about its use |
| From August 2021 onward | Probing systems associated with NATO countries and later targeting systems supporting Ukraine | Alleged in the US indictment, as described by the DOJ |
What the attribution establishes—and what it does not
The September 2024 NCSC statement provides the clearest public allied attribution in the material available here: it identifies Unit 29155 as a cyber actor and describes the activity attributed to it. The UK government profile supplies official context linking the unit’s wider operations to earlier incidents. Bellingcat’s Bulgaria reporting is an investigative account, while the US case remains a set of criminal charges and allegations.
Those distinctions prevent two common errors. First, a charge is not a conviction, so the alleged conduct in the DOJ case should not be presented as established guilt. Second, links between a unit and reported physical operations do not mean those incidents were charged as part of the US cyber case. The sources connect different activities to the same unit, but do so through different forms of attribution.
Recommended Free Tools
NCSC Director of Operations Paul Chichester described the attribution as illustrating “the importance that Russian military intelligence places on using cyberspace to pursue its illegal war in Ukraine and other state priorities.” That is Chichester’s assessment of the significance of the exposure, not a separate judicial finding.
Best Value
- Reference Book
- Modern Russian Tanks & AFVs: 1990-Present Technical Guides Hardcover by Dr.Russell Hart Dr.Stephen Hart Sterling Publishing
What should network defenders do?
The NCSC directs organizations to follow the mitigation guidance in the joint advisory associated with its September 2024 attribution. The public account establishes why defenders should take the unit’s reported cyber activity seriously, but it does not specify individual technical controls in the material summarized here. Organizations should consult that advisory for the applicable measures rather than infer a particular configuration from the attribution alone.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

