- WIADOMOŚCI
- ANALIZA
Europe exposes Russia’s cyber war
The European Union, France and NATO have publicly denounced a wide Russian cyber campaign linked to the Federal Security Service. The message is no longer only that Russia conducts cyber espionage. The message is that Moscow has built an ecosystem in which intelligence services, military units, criminal groups, proxy hackers, malware developers and private companies work around the same strategic objective: pressure against Europe and Ukraine.
On 13 July, the European Union attributed a series of cyber operations to the 16th Centre of Russia’s Federal Security Service, the FSB. France made the same attribution in relation to attacks conducted against French interests with the TURLA intrusion set. NATO also condemned Russia’s persistent malicious cyber activities and stated that they constitute a threat to Allied security. This is important because the accusation is not abstract. It names structures, methods, targets and supporting actors. France, Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland were mentioned among the states targeted by this Russian cyber activity.
The central actor is the 16th Centre of the FSB. According to the French C4 report, this structure, also known as military unit 71330, operates several intrusion sets used against French and European interests. One of them is TURLA, a long-running espionage toolset active since at least 2004. The report also identifies military unit 61240, located in Krasnoye Selo near Saint Petersburg, as responsible for targeting France. This is the key point: France is not only accusing Russia in general, but also defining intelligence structures linked to signals intelligence and offensive cyber activity.
The technical geography of the FSB system also matters. The French report lists eleven interception centres distributed across Russian territory, including units near Sochi, Temryuk, Alushta in Crimea, Balashov, Pskov, Chekhov, Krasnoye Selo, south of Moscow, Khabarovsk, Shkotovo near Vladivostok and Zelenogradsk in the Kaliningrad region. This shows a distributed Russian collection system directed at Europe, the United States and Asia. The presence of a unit in Kaliningrad is especially relevant for NATO’s eastern flank, because the region remains one of Russia’s most important military and intelligence platforms against Europe.
TURLA is the best-known part of this ecosystem. It has been used for intelligence collection against governmental, diplomatic, defence, research, technology, education, media and energy targets. The French report states that since Russia’s full-scale invasion of Ukraine in 2022, TURLA has also supported Moscow’s war effort through intelligence collection against Ukraine and its allies. Its operations involve phishing, watering-hole attacks, exploitation of vulnerabilities, compromise of servers and websites, use of relays, command-and-control infrastructure and data exfiltration. It has also relied on malware families such as Agent.BTZ, Snake, Kazuar, Epic, ComRAT, Carbon, Mosquito, Penguin, Gazer, Crutch, TinyTurla, LightNeuron and Capibar.
France gives concrete examples. Since at least 2017, email accounts of the French Ministry of the Armed Forces have been compromised. In 2018, the network of the French Ministry for Europe and Foreign Affairs at the French Embassy in Moscow was compromised, with network scanning and data exfiltration. In 2019, a justice-sector server was compromised through a SharePoint vulnerability, potentially giving attackers access to several thousand user accounts. In 2025, a French entity working on advanced technologies was targeted. Paris is therefore presenting a long timeline of espionage against strategic state, diplomatic, judicial, defence and technological targets.
Poland also appears in the European assessment. The EU and France indicated that the 16th Centre of the FSB recently conducted cyberattacks in Poland with sabotage objectives against critical infrastructure, including the water sanitation system and the energy sector. This is particularly important for the eastern flank. For Poland, Russian cyber activity cannot be separated from sabotage, disinformation, border pressure, attacks on infrastructure, reconnaissance and attempts to weaken support for Ukraine. Cyber is one instrument inside a wider hybrid campaign.
The EU response targeted not only state structures, but also the support network around them. The sanctions package added individuals and entities linked to several groups and tools: TrickBot, Conti, Wizard Spider, Media Land, ML.Cloud, CARR, Z-Pentest, LummaC2, GRU Unit 29155 and Impuls LLC. This list is important because it shows how Russia’s cyber system really works. Some actors are intelligence officers. Some are military operatives. Some are criminal infrastructure providers. Some are malware developers. Some are self-proclaimed hacktivists. Together, they create an ecosystem useful for espionage, disruption, ransomware, sabotage and deniable operations.
TrickBot and Conti are part of the criminal side of this network. The EU listed Vitaly Kovalev, described as a senior figure in the TrickBot and Conti malware programmes, originally linked to Wizard Spider. These tools have been used in ransomware campaigns against sectors including health and banking, and have caused substantial economic damage in the European Union. This is the logic of modern Russian cyber activity: criminal tools can generate money, create chaos and support broader destabilisation.
Media Land and ML.Cloud represent the infrastructure layer. Media Land is described as a bulletproof hosting service that has facilitated malware attacks since 2016 by offering hosting services that hide user identities and resist takedowns by law enforcement. It enabled ransomware operations, command-and-control services and phishing targeting critical infrastructure and essential services. Operations facilitated by Media Land include LockBit, EvilCorp and BlackBasta. ML.Cloud is presented as a sister company providing technical infrastructure. Without this kind of hosting, many cyber operations are harder to sustain, hide and scale.
CARR, the Cyber Army of Russia Reborn, is the pseudo-hacktivist layer. The EU linked CARR to the Main Centre for Special Technologies within the GRU and noted that it has targeted government agencies, financial institutions, media outlets and critical infrastructure in EU member states, the United States and Ukraine. Denis Degtyarenko and Yuliya Pankratova were listed in relation to CARR. This type of actor is useful for Russia because it can claim ideological motivation while operating in a space that overlaps with state objectives.
Z-Pentest is another pro-Russian hacktivist formation. It is described as a group composed of members from CARR and NoName057, targeting critical infrastructure, especially the energy and water sectors. The EU specifically mentions an attack against a Danish water utility in December 2024. Yuliya Pankratova is linked to Z-Pentest as well as CARR. This is a model Russia uses often: the same individuals and communities move between criminal, ideological and state-linked environments, which makes attribution more complex but not impossible.
LummaC2 is the malware-as-a-service layer. Maksim Voronin and Maksim Gordienko were listed for their alleged role in developing, distributing and selling the LummaC2 information-stealing malware. LummaC2 is used to steal sensitive data, browser credentials, crypto wallets and system information, and can also help deploy further malware on infected devices. The EU notes that in 2024 and 2025 it was one of the most used information-stealing tools worldwide. This matters because stolen credentials are often the first step before larger espionage or sabotage operations.
GRU Unit 29155 and Impuls LLC show the military intelligence connection. The EU listed Evgeniy Bashev and Roman Puntus in connection with GRU Unit 29155, which is accused of cyber activity targeting critical state functions and essential services in member states, notably in the transport sector. Impuls LLC is described as a company providing technical and material support, operational cover, infrastructure, payments and server management for GRU-linked cyber operations. The EU also refers to the WhisperGate campaign against Ukraine’s critical infrastructure. This is not only hacking. It is military intelligence using private structures to support operations below the threshold of open war.
The strategic picture is therefore clear. Russia is not conducting isolated cyberattacks. It is using an entire cyber ecosystem: the FSB for espionage, the GRU for military intelligence operations, criminal groups for ransomware and disruption, bulletproof hosting providers for infrastructure, malware developers for tools and hacktivists for propaganda and plausible deniability. The same ecosystem can steal data from a ministry, attack a water utility, target a defence company, disrupt a website, support operations against Ukraine and intimidate European societies.
NATO’s statement adds the deterrence dimension. The North Atlantic Council condemned Russia’s malicious cyber activities, expressed solidarity with affected Allies and underlined that NATO is ready to use the full range of capabilities to deter, defend against and counter cyber threats. This matters because cyber operations against critical infrastructure and government networks are now part of the Alliance’s security debate, not only a technical issue for national cyber agencies.
The European response is moving in the right direction, but it will have to go further. Attribution and sanctions are necessary, but Russia will not stop because it was named publicly. The real answer must include stronger cyber defence, better intelligence sharing, protection of critical infrastructure, joint exercises, public-private cooperation, faster incident response and political readiness to impose costs. Europe must also prepare for attacks linked to elections, military aid for Ukraine and NATO’s eastern flank.
Russia’s cyber war against Europe is already underway. It is not a future scenario. It is a daily campaign of espionage, disruption, sabotage and pressure. The July attribution shows that Europe understands the structure of the threat more clearly than before. The question now is whether it can respond at the same speed at which Russia’s cyber ecosystem adapts.
This is why NATO and EU countries must treat cyber forces as a permanent element of modern defence, not as an auxiliary technical capability. The evolution of cyber units across all 32 NATO member states shows that cyberspace has become a military domain in which national sovereignty and Allied coordination must work together. Some countries already have mature cyber commands, others are still developing their structures. Every serious state needs forces able to defend networks, support military operations, counter hostile activity and contribute to collective deterrence. Russia’s cyber ecosystem proves that the threat is organised, adaptive and strategic. NATO and the EU therefore need not only sanctions and attribution, but also stronger cyber forces, deeper cooperation, common standards and the ability to respond jointly when hostile cyber operations target critical infrastructure, governments, the defence industry or democratic processes.





