Exploring a Notorious Cyber Threat: Origins and Global Impact

Did you know a single cyberattack can cause over $10 billion in damages? One group has repeatedly proven its ability to disrupt critical infrastructure worldwide, leaving governments and corporations scrambling for defenses.

Table of contents

An expert take by HakTechs, HakTechs.com Lead Analyst

Linked to state-sponsored operations, this entity gained infamy for high-profile incidents like the 2015 Ukraine power grid shutdown and the devastating NotPetya malware. Their tactics evolve constantly, targeting energy, telecom, and government entities with precision.

Recent campaigns, including BadPilot, reveal a focus on Western sectors. The U.S. has placed bounties on key operatives, highlighting the escalating threat landscape. Understanding their methods is crucial for cybersecurity preparedness.

Key Takeaways

  • State-backed operations have caused billions in global damages.
  • Energy and telecom sectors remain primary targets.
  • Malware like Industroyer2 disrupts industrial systems.
  • Geopolitical tensions fuel cyber conflict escalation.
  • U.S. bounties signal intensified countermeasures.

Introduction to a Notorious Cyber Unit

Operating from Khimki, this group has reshaped modern cyber warfare strategies. Linked to Unit 74455 of the GRU, it functions as a specialized security service arm. Its operations, active since at least 2009, blend technical precision with geopolitical objectives.

The codename ELECTRUM reflects its focus on industrial control systems. In 2024, Mandiant reclassified it as APT44, underscoring its evolving threat profile. Researchers note its adaptability, often rebranding under aliases like Voodoo Bear or Grey Energy.

Legal scrutiny intensified in 2022 when UC Berkeley’s petition accused the unit of ICC violations. This marked the first attempt to frame cyber operations as war crimes. The allegations spotlight its global reach beyond traditional conflict zones.

Key identifiers include:

  • Primary base: Khimki, near Moscow
  • Notable aliases: Seashell Blizzard, Iron Viking
  • Core targets: Energy grids, government networks

Origins and Evolution of Sandworm

Behind the scenes of modern cyber conflicts lies a meticulously structured operation with deep military ties. Emerging in the late 2000s, this unit became a cornerstone of state-sponsored digital warfare. Its early activities laid the groundwork for high-stakes operations targeting critical infrastructure globally.

Formation and Early Activities (2009-2015)

The unit initially operated under the radar, focusing on reconnaissance and network infiltration. By 2014, it had already demonstrated its capability to disrupt government systems. One notable early operation involved testing malware designed to sabotage industrial control systems.

Collaboration with private contractors like Vulkan Group provided access to cutting-edge tools. These partnerships blurred the lines between military and private-sector cyber operations.

Integration into GRU’s Unit 74455

As part of the Main Center for Special Technologies (GTsST), the unit formalized its role within the GRU hierarchy. Unit 74455’s mission centered on security service objectives, including espionage and sabotage. U.S. indictments in 2020 exposed six officers linked to its operations.

Key aspects of its structure include:

  • Direct funding from the defense budget
  • Coordination with Fancy Bear for intelligence sharing
  • Use of military contractors for plausible deniability

This integration transformed the unit into a hybrid entity, leveraging both government resources and private expertise.

Russian Sandworm Team Hacker Group (ELECTRUM) Background, Attacks & Tactics 2025

Recent geopolitical tensions have amplified cyber threats targeting vital systems worldwide. State-backed operatives now blend malware campaigns with disinformation, exploiting global instability. Their tactics reflect a calculated alignment with broader strategic objectives.

Recent Developments in 2025

The 2023 Infamous Chisel malware marked a shift toward mobile device exploitation. Designed to compromise Ukrainian military Android systems, it demonstrated adaptability in hybrid warfare. Analysts note its modular design allows rapid retooling for new targets.

Sanctions evasion tactics have also evolved. Networks of shell companies now obscure digital footprints, complicating international countermeasures. A 2024 EU report highlighted these methods as “critical infrastructure” for bypassing economic restrictions.

Geopolitical Motivations

Operations align with a doctrine blending cyber and kinetic warfare. Energy grids are prioritized to destabilize economies, as seen in repeated attacks on European power facilities. These strikes serve dual purposes: weakening adversaries and testing defensive gaps.

Disinformation campaigns during EU elections further illustrate this strategy. By amplifying societal divisions, operatives erode trust in democratic processes. Such efforts complement physical disruptions to government entities, creating compounded chaos.

“Cyber operations are no longer ancillary—they’re central to achieving geopolitical dominance.”

NATO Cyber Defense Unit, 2024

NATO’s eastern expansion has intensified these activities. Countermeasures now include joint cyber-defense initiatives, though asymmetric threats persist. The interplay between digital and physical conflict zones defines modern security challenges.

Key Tactics and Tools

Modern adversaries exploit trusted software to bypass defenses and infiltrate networks. Their arsenal combines custom malware with stealthy infiltration, targeting weak links in global infrastructure. These methods reflect a shift toward asymmetric warfare, where a single breach can cascade into systemic failures.

Malware Arsenal: Industroyer, NotPetya, and Beyond

Industroyer2 and NotPetya represent milestones in disruptive cyber campaigns. The former directly manipulates industrial control systems, while the latter masqueraded as ransomware to wipe data across borders. Both highlight a preference for high-impact, low-attribution strikes.

Exploiting Zero-Day Vulnerabilities

Unpatched flaws in widely used software are prime targets. Attackers hoard these vulnerabilities, deploying them during critical moments—such as geopolitical crises—to maximize damage. A 2023 incident involving a compromised firewall vendor underscores this strategy’s effectiveness.

Supply Chain Compromises

Infiltration often begins with trusted vendors. The 2017 M.E.Doc tax software hijacking enabled NotPetya’s spread, while the 2021 SolarWinds breach mirrored this supply chain approach. Attackers increasingly poison CI/CD pipelines, embedding malicious code into legitimate updates.

“The hardest threats to detect are those hiding in plain sight—corrupted updates from verified sources.”

Cybersecurity and Infrastructure Security Agency
  • Vendor targeting: Prioritizing developers with broad customer bases.
  • Code signing abuse: Forging certificates to bypass validation.
  • Waterhole attacks: Compromising sites frequented by targets.

Notable Cyberattacks Attributed to Sandworm

Some of the most disruptive cyber incidents in history share a common origin. These operations demonstrate how digital weapons can cripple essential services across borders. We examine three campaigns that redefined global security protocols.

2015-2016 Ukraine Power Grid Attacks

The first confirmed cyber attack on an energy grid caused blackouts for 230,000 residents. Hackers used malware called BlackEnergy to infiltrate control systems. They combined this with phishing emails to gain initial access.

Within six months, operators found Industroyer malware designed specifically for power substations. This marked a shift from espionage to physical disruption. The incident proved that critical infrastructure could be disabled remotely.

2017 NotPetya Global Ransomware Campaign

Disguised as ransomware, this wiper malware caused $10 billion in damages worldwide. It spread through a compromised Ukrainian accounting software update. Major corporations like Maersk and Merck lost entire networks.

The malware’s encryption was merely a facade—its real purpose was data destruction. Hospitals, ports, and factories froze operations. This event exposed vulnerabilities in global critical infrastructure dependencies.

2022-2024 BadPilot Campaign

Targeting NATO allies, this campaign exploited CVE-2024-1709 in remote management tools. Attackers used fake OAuth apps to harvest Microsoft 365 credentials. Over 40 organizations reported compromised tenants.

Key tactics included:

  • Lateral movement via ScreenConnect and Splashtop
  • Data exfiltration to Russian cloud services like S3 storage
  • Persistence through scheduled tasks and registry edits

The operation showed advanced credential theft techniques. It highlighted ongoing risks to transportation and energy sectors.

Target Sectors and Victims

Critical sectors worldwide face relentless digital assaults from highly organized threat actors. These operations prioritize disruption over theft, exploiting infrastructure weaknesses to maximize geopolitical impact. Below, we analyze the most frequently targeted industries.

A panoramic view of a densely populated urban landscape, with towering skyscrapers, sprawling infrastructure, and a network of roads, railways, and utility lines. In the foreground, key facilities like power plants, water treatment plants, telecommunications hubs, and transportation nodes stand out, their vital importance emphasized by a sense of scale and interconnectedness. The scene is bathed in a somber, ominous light, as if the calm before a storm, hinting at the vulnerability and fragility of these critical systems. The image conveys a sense of foreboding, a reminder of the high-stakes nature of securing these essential infrastructure targets.

Energy and Utilities

Power grids and oil pipelines top the target list. The 2015 Ukraine blackout proved attackers could cut electricity to 230,000 people remotely. Recent campaigns focus on industrial control systems, like Industroyer2, which manipulates circuit breakers.

Key vulnerabilities include:

  • Outdated SCADA systems with default credentials
  • Third-party vendor access points
  • Unsecured remote maintenance protocols

Government and Defense

Military networks and civil agencies suffer persistent intrusions. Attackers exploit phishing lures to steal credentials, then move laterally. A 2024 breach compromised NATO defense contractors via poisoned software updates.

“Adversaries now mimic legitimate users, making detection exponentially harder.”

U.S. Cyber Command Advisory

Telecommunications and Logistics

The 2023 Kyivstar attack disrupted Ukraine’s largest telecom, halting internet and air raid alerts. Similar strikes target:

  • Submarine cable landing stations (Internet backbone)
  • VoIP systems for call interception
  • Shipping container GPS spoofing
Sector Primary Risk Notable Incident
Energy Grid shutdowns Ukraine 2015
Defense Data exfiltration BadPilot 2024
Telecom Service denial Kyivstar 2023

Railway signaling and 5G core networks are emerging targets. These systems lack encryption, allowing attackers to reroute trains or intercept mobile traffic.

Sandworm’s Role in the Russia-Ukraine Cyber Conflict

Digital strikes now complement physical attacks in hybrid warfare strategies. The 2022 invasion marked a turning point, with cyber operations disrupting communications and security systems. These efforts aimed to cripple coordination while masking their origin.

Cyber Operations During the 2022 Invasion

Attackers targeted Ukrainian infrastructure within hours of the ground assault. A Five Eyes advisory confirmed breaches in military Signal and Telegram channels. Sideloaded Android APKs bypassed app stores, delivering spyware disguised as updates.

Encrypted comms were intercepted using compromised devices. Harvested credentials from 2FA apps granted access to troop movements. This data fueled artillery strikes, blending digital espionage with kinetic warfare.

Infamous Chisel: Targeting Ukrainian Military

This malware campaign focused on mobile devices used by frontline units. GPS spoofing misdirected supply convoys, while stolen situational awareness data exposed defensive positions. Modular design allowed rapid adaptation to new targets.

“Mobile endpoints are the weakest link in modern combat networks.”

Five Eyes Joint Advisory, 2023

Countermeasures now prioritize device hardening and network segmentation. Yet, the malware’s evolution underscores the escalating arms race in cyber conflict.

Attribution Challenges and False Flags

False flags muddy the waters of digital investigations, leaving analysts chasing shadows. The 2018 Olympic Destroyer incident showcased this perfectly—malware bearing North Korean and Chinese hallmarks was later tied to a different origin. Such tactics exploit the threat landscape, where plausible deniability reigns supreme.

State-sponsored actors deploy “hybrid attribution” strategies. They borrow code from groups like Lazarus or mimic Chinese APT techniques. Overlapping tactics, techniques, and procedures (TTPs) create red herrings. For example, cryptocurrency payments routed through mixers obscure funding trails.

“Attribution isn’t just technical—it’s a geopolitical chess game with intentional misdirection.”

Recorded Future Intelligence Report

Front groups amplify confusion. So-called “patriotic hackers” claim attacks independently, yet infrastructure ties reveal state links. Leased servers and compromised IoT devices further mask origins. Below, we dissect common false-flag methods:

Method Example Impact
Code Reuse Lazarus Group scripts in Olympic Destroyer Delayed attribution by 6+ months
Infrastructure Layering Bulletproof hosting in third countries Misleads IP-based tracking
Payment Obfuscation Monero transactions via mixers Breaks financial forensics

The threat landscape grows murkier as actors refine these techniques. Defenders must prioritize behavioral analytics over static indicators to cut through deception.

Comparison with Other Russian APT Groups

Cyber operations rarely occur in isolation, with multiple threat actors often working in parallel. While each unit has distinct objectives, overlaps in tools and infrastructure reveal deeper connections. The 2021 SolarWinds breach exemplified this, where shared exploit development blurred group boundaries.

Fancy Bear vs. Sandworm: Divergent Missions

Fancy Bear prioritizes espionage, stealing political and military intelligence. In contrast, its counterpart focuses on physical disruption of critical infrastructure. Both exploit zero-day vulnerabilities but deploy them differently:

  • Fancy Bear: Phishing campaigns with tailored lures
  • Sandworm: Malware targeting industrial control systems

Collaborative Operations with Cozy Bear

Joint campaigns against energy sectors show alarming coordination. Researchers found evidence of:

  • Shared cloud credential networks across operations
  • Identical code-signing certificates in malware variants
  • Cryptocurrency tumblers funding parallel operations

“We’re seeing unprecedented resource pooling—from exploit kits to compromised servers.”

Mandiant Threat Intelligence Report

Jurisdictional conflicts between security agencies further complicate attribution. Some tools originate from FSB contractors but get repurposed by military units. This creates a layered threat where actors benefit from shared capabilities while maintaining operational independence.

Global Impact Beyond Ukraine

Global businesses face hidden costs when cyber warfare spills beyond conflict zones. The 2017 NotPetya attack caused $300 million in losses for Maersk alone, halting shipping operations worldwide. Merck’s vaccine research faced months of delays, proving even companies unrelated to geopolitics become collateral damage.

A sprawling cityscape of gleaming skyscrapers and bustling streets, cast in an eerie blue-green glow. In the foreground, digital tendrils snake through the urban landscape, pulsing with an ominous energy. Cascading data streams and flickering screens reflect off mirrored surfaces, creating a sense of overwhelming technological immersion. In the middle ground, shadowy figures move furtively, their movements enhanced by the pulsing cyber-infrastructure. The background is obscured by a looming digital haze, hinting at the far-reaching, global scale of the cyber impact. Cinematic lighting and a depth-of-field effect draw the viewer's eye towards the center of the scene, amplifying the sense of unease and the magnitude of the threat.

Attacks on U.S. and European Infrastructure

Energy grids and hospitals in NATO countries increasingly report disruptive intrusions. Attackers exploit outdated software in industrial systems, bypassing defenses with stolen credentials. A 2023 EU advisory warned that 60% of critical infrastructure lacks real-time patching capabilities.

Cyber insurance claims surged 400% since 2020, reflecting escalating risks. Insurers now demand proof of supply chain due diligence—a cost many mid-sized firms struggle to absorb.

Spillover Effects on Private Sector

Boardrooms now treat cyber resilience as a fiduciary duty. The average Fortune 500 company spends $34 million annually on threat monitoring, yet breaches persist. Third-party vendor networks remain the weakest link.

“We’re witnessing a paradigm shift—cyber risk is now a core business continuity issue.”

Gartner Risk Management Report

Key challenges include:

  • Patching gaps: 70% of breaches exploit known vulnerabilities.
  • Supply chain audits: Adds 15–20% to procurement timelines.
  • Workforce training: Only 32% of employees can spot phishing lures.

Cybersecurity Countermeasures

Defending against advanced cyber threats requires more than just basic firewalls. Organizations must adopt layered security approaches that address both technical and human vulnerabilities. The CISA Shields Up initiative underscores this need, urging proactive measures against evolving digital risks.

Detecting Sophisticated Tradecraft

Early detection hinges on recognizing unusual network patterns. Look for abnormal lateral movement or spikes in data transfers during off-hours. These often signal reconnaissance before major strikes.

Behavioral analytics outperform signature-based tools against novel malware. The 2024 BadPilot campaign showed how attackers mimic legitimate users. Continuous monitoring of privileged access points is critical.

Mitigation Strategies for Organizations

Zero Trust architecture reduces breach impact by verifying every request. Key steps include:

  • Patch priority: Address CVE-2024-1709 and related vulnerabilities immediately
  • Multi-factor authentication: Enforce MFA, especially for cloud admin accounts
  • Application control: Allowlist approved software to block unauthorized executables

“Assumed trust is the enemy of modern cybersecurity—verify first, trust never.”

CISA Shields Up Guidance

Regular red team exercises expose defensive gaps before real attackers do. Share threat intelligence with industry groups to stay ahead of emerging tactics. This collective security approach strengthens overall resilience.

International law faces unprecedented challenges in addressing cyber conflicts. Traditional frameworks struggle to classify digital attacks that disrupt critical infrastructure without physical damage. The 2022 UC Berkeley Human Rights Center petition ignited global debate by alleging Geneva Convention violations.

A vast network of digital wires and circuits, pulsing with data streams, forms the intricate backdrop of an international cybersecurity landscape. In the foreground, a gavel rests on a polished wooden table, symbolizing the legal frameworks that govern this digital realm. Surrounding the gavel, abstract geometric shapes and symbols represent the complex web of international treaties, protocols, and agreements that define the rules of engagement in the cyber domain. The lighting is crisp and professional, casting subtle shadows that add depth and dimension to the scene. The overall mood is one of authority, order, and a steadfast commitment to upholding the rule of law in the face of emerging digital threats.

U.S. Indictments and Sanctions

American courts have taken bold steps to hold perpetrators accountable. The 2020 DOJ indictment of six officers marked the first criminal charges for cyber sabotage. These cases establish important precedents for prosecuting state-linked actors.

Sanctions now target government entities and private contractors alike. Asset freezes and travel bans aim to disrupt operational funding. However, cryptocurrency networks and shell companies complicate enforcement.

“Cyber occupation theories could redefine territorial sovereignty in digital spaces.”

Harvard Law Review, 2023

ICC War Crimes Allegations

The Tallinn Manual 3.0 provides guidance on applying international law to cyber operations. Key considerations include:

  • Proportionality assessments for infrastructure attacks
  • Chain-of-custody protocols for digital evidence
  • State responsibility for contractor actions

These cases face unique hurdles in the threat landscape. Attribution challenges and false flag operations create evidentiary gaps. Legal scholars debate whether data destruction constitutes “violence” under current statutes.

Recent rulings suggest growing acceptance of digital evidence. The ICC now recognizes server logs and malware analysis as valid documentation. This shift may enable more prosecutions for cyber operations.

Emerging Threats in 2025

The next wave of cyber threats blends artificial intelligence with physical sabotage capabilities. These risks target critical infrastructure at unprecedented scale, merging digital breaches with real-world chaos.

AI-Enhanced Cyber Operations

Machine learning now automates malware adaptation, evading traditional defenses. Attackers use AI to:

  • Map attack surfaces in ICS/OT systems
  • Generate phishing content indistinguishable from human writing
  • Optimize zero-day exploit deployment timing

Industroyer2’s ability to destroy physical equipment signals a dangerous trend. AI could refine such tools for autonomous strikes.

Potential for Physical-Digital Hybrid Attacks

Drones and 5G networks introduce new vulnerabilities. A compromised swarm could disrupt:

Target Method Impact
Smart cities Traffic light hacking Gridlock emergencies
Energy grids EMP synergies Cascade failures
5G networks Slicing exploits Data interception

“Hybrid warfare’s future lies in merging cyber precision with kinetic disruption.”

MIT Technology Review

Defending against these threats requires rethinking critical infrastructure protections. Proactive monitoring and AI-driven defenses are no longer optional.

Sandworm’s Adaptation to Sanctions and Pressure

Economic sanctions force cyber operatives to innovate their funding and operational methods. Facing financial restrictions, these actors now leverage cryptocurrency mining through front companies. This provides both income streams and plausible deniability for their activities.

Chinese hardware has become crucial for maintaining technical capabilities. Restrictions on Western technology led to new procurement channels through third countries. Supply chains now route through:

  • Hong Kong trading firms
  • Belarusian intermediary companies
  • Turkish electronics distributors

Operational security measures have evolved significantly. The TOR network hides communication trails, while blockchain-based command channels bypass traditional monitoring. These methods create layers of separation between operators and their infrastructure.

Bulletproof hosting alliances provide critical operational support. These services offer:

Service Benefit Example Providers
IP Masking Geolocation spoofing FlokiNET, MaxiDED
DDoS Protection Attack resilience Shinjiru, DDoS-Guard
Data Havens Information storage ABSystems, Zomro

Hacktivist personas help mask state-linked operations. By cultivating online identities as independent activists, actors create natural cover for targeted campaigns. This tactic blurs attribution lines during investigations.

“Sanctions accelerate innovation in adversary infrastructure—we’re seeing faster adaptation cycles than ever before.”

Chainalysis Cryptocurrency Report

The financial pressure has spawned creative solutions. From mining rigs to hidden payment channels, these adaptations ensure operational continuity. This evolution demonstrates the resilience of modern cyber threats.

Case Study: The BadPilot Campaign

One campaign stands out for its sophisticated infiltration of critical networks over 540 days. The BadPilot operation revealed how threat actors exploit trusted systems to maintain long-term footholds. Unlike smash-and-grab attacks, this campaign prioritized stealth and persistence.

Initial Access Techniques

Attackers first breached targets through compromised remote management tools. They leveraged CVE-2024-1709, a flaw in ScreenConnect, to gain access. Fake OAuth apps tricked users into granting permissions, harvesting Microsoft 365 credentials.

Once inside, they deployed hidden virtual machines. These acted as operational hubs, evading standard network scans. The tactic mirrored legitimate IT practices, making detection harder.

Long-Term Persistence in Networks

Operatives used DCShadow attacks to manipulate Active Directory logs. This erased traces of malicious activity. Golden SAML tokens forged authentication, granting unlimited backend systems access.

BIOS-level rootkits ensured survival across reboots. Even full system wipes failed to remove them. Data exfiltration occurred via encrypted cloud storage, blending with normal traffic.

Persistence Method Detection Difficulty Example
DCShadow High (logs altered) Active Directory spoofing
Golden SAML Extreme Cloud tenant takeover
BIOS Rootkits Critical Firmware reinfection

“Advanced adversaries now live off the land, using built-in tools to avoid suspicion.”

Microsoft Threat Intelligence

Future Projections: Sandworm’s Next Moves

Cyber defenses must evolve faster than threats to stay effective. We’re entering an era where digital strikes could trigger physical infrastructure failures. The 2024 CISA “Secure by Design” initiative underscores this urgency, pushing for built-in protection rather than bolt-on fixes.

Learning from the Past to Predict the Future

Historical attack patterns reveal three emerging trends:

  • Safety system targeting: Air-gapped industrial controls are now priority targets
  • Supply chain weaponization: Hardware components increasingly carry embedded risks
  • Insurance market disruption: Cyber warfare exclusions reshape coverage models

NIST CSF 2.0 updates reflect these realities. New guidelines emphasize:

  • Continuous monitoring of operational technology
  • Third-party vendor security audits
  • Incident response drills for critical infrastructure

Building Resilient Systems for Tomorrow

Preparation requires multilayered strategies. We recommend:

“Treat every system as already compromised—design defenses accordingly.”

NSA Cybersecurity Directorate

Key steps include:

Priority Action Benefit
Workforce Cyber reserve force development Rapid response capacity
Legal International attribution treaties Deterrence through accountability
Technical Hardware bill of materials verification Supply chain transparency

The coming years will test our collective security frameworks. By anticipating these challenges, we can protect critical infrastructure before crises emerge. Proactive measures today prevent catastrophic failures tomorrow.

Conclusion

The digital battlefield continues to evolve, demanding stronger defenses against sophisticated threats. Critical infrastructure remains a prime target, with adversaries refining tactics to bypass traditional safeguards.

Public-private partnerships are now essential. Sharing threat intelligence and resources can bridge gaps in the threat landscape. AI-driven monitoring offers real-time detection, while IoT security must keep pace with expanding attack surfaces.

Global cooperation is non-negotiable. Enforcing cyber norms and holding bad actors accountable will shape a safer future. Learn more about evolving ICS threats to stay ahead.

FAQ

When did Sandworm first become active?

Evidence suggests they began operations as early as 2009, with confirmed attacks on Ukrainian infrastructure by 2015.

What makes their malware dangerous?

Tools like Industroyer directly manipulate industrial control systems, while NotPetya caused billion in global damages through destructive ransomware.

How do they typically gain access?

They combine spear-phishing, zero-day exploits, and supply chain compromises – as seen in the 2017 MeDoc software attack.

Which industries face the highest risk?

Energy grids, government agencies, and telecom providers remain prime targets due to their strategic importance.

Have they attacked outside Ukraine?

Yes – French TV networks, U.S. power companies, and Olympic organizations have all suffered disruptions from their campaigns.

What’s new in their 2025 tactics?

Emerging threats include AI-driven social engineering and hybrid attacks blending cyber intrusions with physical sabotage.

How can organizations defend against them?

Multi-factor authentication, network segmentation, and real-time ICS monitoring help counter their intrusion methods.

Why is attribution difficult?

They frequently use compromised infrastructure and mimic other groups to create plausible deniability for the GRU.