The United States (US) and its allies have linked a group of Russian hackers (tracked as Cadet Blizzard and Ember Bear) to attacks on critical infrastructure around the world. Authorities believe this group consists of Russian military hackers, affiliated with Unit 29155 of the Main Directorate of the General Staff of the Russian Armed Forces (also known as the GRU).

The US says Russian GRU hackers used the WhisperGate malware , which targeted Ukraine in January 2022.
The hackers are described as "junior active-duty GRU officers" part of the GRU's 161st Specialist Training Center coordinated by the experienced leadership of Unit 29155.
See also: Russian hackers suspected of cyberattack on Deutsche Flugsicherung
The group is behind sabotage and assassination attempts across Europe, and has carried out numerous cyberattacks against critical infrastructure in NATO members, North American countries, Europe, Latin America, and Central Asia. These attacks often target cyberespionage, data theft and leakage, reputational damage , and have been ongoing since 2020. However, since 2022, Ukraine and the countries that provided assistance to it in its war with Russia have been targeted.
“These individuals appear to be gaining cyber experience and enhancing their technical skills through conducting operations and intrusions. In addition, the FBI assesses that Unit 29155 attackers rely on non-GRU actors, including known cybercriminals and other facilitators to conduct their activities.“.
The FBI says it has identified more than 14,000 instances of domain scanning targeting at least 26 NATO members and several European Union (EU) states. Hackers, associated with Russia's Unit 29155, have also been linked to attacks defacement and have used public domains to leak stolen data.
See also: Russian hackers use exploits created by NSO Group and Intellexa
The U.S. State Department has announced a reward of up to $10 million through its Rewards for Justicefor information leading to the arrest of Vladislav Borovkov, Denis Igorevich Denisenko, Yuriy Denisov, Dmitry Yuryevich Goloshubov, and Nikolay Aleksandrovich Korchagin, five officers in the Russian military intelligence department believed to be members of GRU Unit 29155.
"These individuals are members of Unit 29155 of the Main Intelligence Directorate of the Russian General Staff (GRU), which conducted malicious cyber activity against critical U.S. infrastructure, particularly in the energy, government, and aerospace," the State Department said.
“These officers of GRU Unit 29155 are responsible for targeting critical infrastructure in Ukraine and dozens of allied Western countries,” he said.

The five GRU officers were also accused of participating in cyberattacks against 26 NATO members and against Ukraine before Russia's invasion in February 2022.
As the world becomes more dependent on technology, the potential for cyberattacks to cause significant damage increases. It is important that both governments and private sector organizations prioritize measures cybersecurity and invest in regularly updating their systems to protect against these threats. In addition, international cooperation and information sharing can help identify malicious actors such as Russian military hackers.
It is also important for nations to focus on defensive measures but also take proactive steps to deter cybercriminals . This may include imposing sanctions or other consequences on state-sponsored hacking groups, as well as working to enact regulations that discourage such behavior.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian hackers stole UK government data
In addition, it is necessary to address the root causes of cyberattacks, including geopolitical tensions and ideological differences. Addressing these issues through diplomatic channels and enhancing understanding between nations can help reduce the likelihood of cyberattacks originating from state actors.
Source: www.bleepingcomputer.com
