Skip to content
The Nexus
DossierENTITY

GRU

Coverage of GRU in the Nexus archive.

Earliest in view: Apr 8 · 11:00 UTCMost recent: Jul 19 · 13:30 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 19 · 13:30 UTCTHE HACKER NEWS
    UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

    Russian state-sponsored threat actors have used ClickFix CAPTCHAs to trick Ukrainian targets into installing data-stealing malware. The activity is attributed to UAC-0145, a sub-cluster of Sandworm, an advanced hacking unit linked to Russia's GRU.

  • SECURITYJul 13 · 21:08 UTCKYIV POST
    EU, UK Hit Russia With Joint Sanctions Over Cyber Attacks

    The EU and UK imposed joint sanctions on Russian officials from the FSB and GRU over cyberattacks, including a foiled attack on Poland's power grid. Brussels sanctioned nine individuals and four entities, while London added 24 names to its blacklist. Separate EU sanctions targeted 15 individuals, including an Olenivka prison official, for abuse of Ukrainian POWs and detainees.

  • SECURITYJul 13 · 16:28 UTCCYBERSCOOP
    Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’

    European governments sanctioned Russian individuals and organizations linked to cyberespionage group Turla and destructive attacks, including FSB's Center 16 and GRU figures. The EU and UK cited Turla's 2010–2023 operations targeting European nations and Poland's 2022 energy grid attack.

  • SECURITYJul 10 · 08:42 UTCDEFENSE NEWS
    Italy busts Russian spy ring collecting data on Ukrainian air defense vulnerabilities

    Italy dismantled a Russian spy ring collecting data on Ukrainian air defense systems, including Europe’s Samp-T and Italy’s Michelangelo Dome. A former Italian intelligence official, Gavino Piras, allegedly provided information to a Russian GRU officer, Mikhail Astakov, in exchange for cash payments.

  • SECURITYJun 14 · 17:01 UTCFOX NEWS
    FBI says Russian hackers hijacked old Wi-Fi routers

    The FBI and Justice Department warned that Russian hackers linked to the GRU exploited vulnerabilities in outdated SOHO routers to conduct espionage by altering DNS settings and intercepting traffic. The hackers redirected internet requests through their servers to steal sensitive data, and authorities disrupted the U.S. portion of the network in April.

  • SECURITYJun 10 · 15:40 UTCTHE CIPHER BRIEF
    Russian Active Measures, And More Dirty Tricks: Expect Russia to Escalate Its Attacks on our Democracies

    The article discusses Russia's historical use of 'active measures' to disrupt democracies, highlighting recent operations in Europe targeting ethnic minorities through defacement and divisive tactics. It notes the evolution of these strategies with AI and cognitive warfare, emphasizing the role of Russian intelligence agencies like the SVR, GRU, and FSB in undermining Western political systems.

  • SECURITYJun 2 · 13:51 UTCTHE CIPHER BRIEF
    From Terror Networks to Hybrid Threats: A Partner Approach to a Growing Threat

    The article draws parallels between current European hybrid threats and post-9/11 terrorism, urging adaptation of counterterrorism cooperation models. It highlights Russia and Iran's use of proxies and digital platforms to recruit individuals for sabotage and assassination plots, which align with the FBI's definition of international terrorism. The U.S. counterterrorism strategy acknowledges collaboration with European partners to address these covert state actions.

  • POLITICSMay 25 · 23:00 UTCRECORDED FUTURE NEWS
    Kremlin appoints cyber executive with alleged GRU ties to Security Council role

    Andrei Kozlov, a former cybersecurity center head at Rostec, was appointed as an aide to Security Council Secretary Sergei Shoigu. He has alleged ties to Russia's GRU military intelligence agency.

  • SECURITYApr 8 · 11:00 UTCARS TECHNICA
    Thousands of consumer routers hacked by Russia's military

    The Russian military, through the APT28 group linked to the GRU, has hacked 18,000 to 40,000 consumer routers in 120 countries. These routers were used to spy on government agencies and alter DNS settings for Microsoft's 365 service. Researchers from Lumen Technologies' Black Lotus Labs reported the breach.