Skip to content
Profile Gru Cyber And Hybrid Threat Operations

Profile Gru Cyber And Hybrid Threat Operations

www.gov.uk • August 25, 2026

This publication is licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open-government-licence/version/3 or write to the Information Policy Team, The National Archives, Kew, London TW9 4DU, or email: [email protected] .

Where we have identified any third party copyright information you will need to obtain permission from the copyright holders concerned.

This publication is available at

To date, the United Kingdom has:

GRU Units 29155, 26165 and 74455 are 3 entities with known cyber capabilities. Units 26165 and 74455 represent an advanced, comprehensive cyber capability which Russia deploys for the achievement of military and foreign policy objectives. Unit 29155 also separately carries out operations against these targets.

These units have the following titles:

Following Russia’s full-scale invasion of Ukraine, it has been reported that the Special Activity Service (“SSD”) was established to absorb GRU Unit 29155 and to conduct operations against the West using Russia’s full hybrid toolkit, including sabotage, assassinations and cyber attacks. According to public reporting, Ivan Sergeyevich Kasyanenko has held the position of Deputy Chief of The Special Activity Service (also known as the Department of Special Tasks or SSD). It has been reported that Kasyanenko works closely with SSD’s Chief Andrey Averyanov.

Wider GRU Unit 29155 operations include the Vrbétice ammunition warehouse explosions in Czechia (2014) and the attempted murder of Yulia and Sergei Skripal in Salisbury (2018). GRU Unit 29155’s cyber division has specifically targeted Ukraine, The Eastern Neighbourhood and NATO’s Eastern Flank with cyber-attacks across multiple fronts, including foreign governments, defence organisations, Russian dissidents and think tanks.

Widespread credible evidence indicates that these cyber incidents are linked to Unit 29155:

Unit 29155’s cyber wing is a recently developed part of the GRU’s cyber capability. Comprised mainly of young recruits working under seasoned handlers, the Unit has a range of capabilities but is ill-disciplined and haphazard in how it conducts its operations. This group is known for carrying out disruptive and destructive cyber operations including deploying a wiper malware known as ‘Whispergate’ on over 70 Ukrainian government systems in the build-up to Russia’s invasion of Ukraine.

GRU Unit 29155’s cyber division has specifically targeted Ukraine, The Eastern Neighbourhood and NATO’s Eastern Flank with cyber-attacks across multiple fronts, including foreign governments, defence organisations, Russian dissidents and think tanks.

GRU Unit 29155 military intelligence officers Dmitriy Voronov, Aleksandr Shepelev and Roman Puntus have all played key roles in conducting these operations, including tasking and funding of Russian cybercriminals Sultan Omarov, Evgeniy Bashev and his publicly listed front company “OOO IMPULS” to expand GRU capabilities and conduct deniable operations. GRU Unit 29155 officers funded Bashev’s company IMPULS for surveillance and reconnaissance operations.

Bashev and IMPULS were also deployed to recruit hackers and cyber specialists for Unit 29155 from universities and academies across Russia. Public reporting indicates that Yuriy Denisov was a recruiter and a more seasoned GRU Unit 29155 officer, whilst Dmitriy Goloshubov, Nikolai Korchagin, Denis Denisenko, Vladislav Borovkov and Vitaliy Shevchenko are among those recruited as cyber officers into Unit 29155 via this method.

Unit 26165 is a highly sophisticated, well-established cyber actor which conducts both advanced intelligence gathering and hack and leak operations – against Ukraine, European partners, NATO allies and the UK – in support of Russia’s foreign policy and military objectives.

The UK designated fourteen military intelligence officers from GRU Unit 26165 in 2025. This has involved exposing 6 Unit 26165 military intelligence officers for the first time.

GRU Unit 26165 is comprised of multiple teams, focusing on different aspects of the GRU’s cyber and hybrid operations. Three relevant teams include an Operations Team (Ops), Development Operations Team (DevOps) and an Operational Infrastructure Team.

Boris Antonov continues to hold a senior leadership position in Unit 26165, where he directs the efforts of the Operations Team within the Unit. He is a longstanding GRU military intelligence officer who has been exposed by multiple countries for his membership of, and activity within, GRU Unit 26165. He was first exposed by the FBI and US Department of Justice (DOJ) in 2018. The Operations Team is responsible for targeting military, political, governmental and non-governmental organisations with spear phishing, brute force attacks, CNE/CVE exploits, social engineering, zero-day exploits and other computer intrusion operations. Aleksey Lukashev, Ivan Yermakov and Andrey Baranov were all members of this team.

Sergey Morgachev was responsible for leading a Development Operations Team (DevOps) within the unit. This team is responsible for developing and managing Unit 26165 malware, including X-Agent and a data exfiltration tool known as X-Tunnel. Nikolai Kozachek, Artem Malyshev and Pavel Yershov were all members of this team.

Anatoliy Istomin was responsible for leading an Operational Infrastructure Team within Unit 26165, directing the efforts of military intelligence officers including, but not limited, to Igor Bochka, Aleksey Umets and Sergey Vasyuk. This team and its members conduct a range of operational activities including infrastructure procurement, testing and set up, data exfiltration and open-source research and reconnaissance support to Unit 26165 operations focused on Ukraine.

Anatoliy Istomin worked closely with, and gave instruction to, Sergey Vasyuk on managing Unit 26165 operational infrastructure used to exfiltrate data from a range of victims. For example, Igor Bochka managed Unit 26165 operational infrastructure used to assist the GRU’s operation to hack the United States Democratic National Committee (DNC) and Democratic Congressional Campaign Committee (DCCC). Furthermore, Anatoliy Istomin, Igor Bochka and Aleksey Umets were all involved in the procurement and development of Drovorub (Russian: woodcutter) malware used in a range of GRU Unit 26165 operations.

There are suggestions that Sergey Vasyuk trained and assisted Aleksey Umets when he first joined GRU Unit 26165. Vasyuk and Umets are likely just one example of this. It is common practice for junior GRU Unit 26165 military intelligence officers to be paired with a more experienced colleague to train them in a range of operational tasks.

Widespread credible evidence indicates that these additional incidents are linked to Unit 26165:

Unit 74455 is a highly sophisticated, longstanding cyber actor, specialising in destructive cyber operations. Unit 74455 principally targets critical national infrastructure (CNI), industrial control systems (ICS), and entities of strategic interest to Russia including Ukrainian military and governmental targets.

Widespread credible evidence indicates that these incidents are linked to Unit 74455:

Development of X-Agent malware for GRU Unit 26165 was led by Sergey Morgachev and involved Anatoliy Istomin, Aleksey Lukashev, Ivan Yermakov, Sergey Vasyuk and Artem Malyshev in various different capacities. Unit 26165 has extensive, longstanding malware development capabilities and has used X-Agent and X-Tunnel malware in cyber intrusion operations, including in support of warfighting activities. For example, according to credible open-source reporting, X-Agent has been deployed by Unit 26165 for geolocation purposes to identify Ukrainian military hardware in Donbas between 2014 and 2016, enabling Russia to conduct artillery strikes on Ukrainian positions. In the UK context, Aleksey Lukashev, Ivan Yermakov and GRU Unit 26165 conducted historic cross-border targeting of email accounts belonging to Yulia Skripal with X-Agent malware, which took place in 2013. In 2018 GRU Unit 29155 attempted to murder Yulia and Sergei Skripal with a Novichok nerve agent, a substance banned under the Chemical Weapons Convention (CWC), on UK sovereign territory.

On 10 to 13 April 2018, Aleksey Morenets, Yevgeniy Serebriakov, Oleg Sotnikov and Aleksey Minin travelled to the Hague to conduct close access operations on the Organisation for the Prohibition of Chemical Weapons (OPCW). These individuals acted on behalf of Unit 26165 at this time. The same unit and individuals then intended to target the Spiez Swiss Chemical Laboratory, an OPCW-accredited facility. Additionally, Unit 26165 and Unit 74455 attempted cyber intrusion operations to gain access to the Foreign, Commonwealth and Development Office (FCDO) in March 2018 and UK’s Defence, Science and Technology Laboratory (DSTL) in April 2018.

The UK is exposing the role of GRU Unit 26165 and GRU Unit 74455 in cyber operations, including Unit 26165’s initial targeting of Yulia Skripal’s emails through to both Unit 26165 and Unit 74455’s attempts to interfere investigations into the attempted murder of Yulia and Sergei Skripal at the hands of GRU Unit 29155. This case study underscores how GRU Units integrate cyber operations into hybrid activity with the aim of furthering the Kremlin’s objectives.

Since Russia’s full-scale invasion of Ukraine on 24 February 2022, the GRU has used cyber operations in support of Russia’s military campaign to achieve the following aims:

The below incidents illustrate that all 3 units have been active in Ukraine.

The UK is sanctioning Victor Lukovenko, Artyom Kureyev and Anna Zamarayeva for their role in the interference agency African Initiative. These sanctions highlight the hybridity of Russian operations and their expansion beyond Europe.

African Initiative launched in September 2023. It maintains a growing presence online and, since its launch until 30 April 2025, its website has published over 18,000 articles in French, Arabic, Spanish, Russian and English. It also produces content on a number of social media channels. The African Initiative was established in coordination with Russia, employs Russian intelligence officers, and receives funding from Russia for influence operations in the region.

Artyom Sergeyevich Kureyev is the Editor-in-Chief of Africa Initiative; he has additionally been linked to a role in the Russian FSB. Other individuals involved in African Initiative include Anna Sergeyevna Zamarayeva, the Deputy Editor-in-Chief. Anna Zamarayeva is known to have been employed as a spokesperson for the now defunct PMC Wagner. GRU linked Victor Aleksandrovich Lukovenko, alias Viktor Vasilyev, was a liaison officer with African Initiative’s local offices and produced a number of articles for the African Initiative website.

African Initiative develops and distributes content which undermines Ukraine’s Armed Forces and has organised a press tour to Mariupol, illegally occupied by Russia, for a delegation of bloggers and journalists.

Yuliya Pankratova and Denis Degtyarenko are key members of hacktivist groups CARR (People’s Cyber Army of Russia) and Z-Pentest Alliance. Since their creation in early 2022, both groups have conducted reckless cyber operations targeting critical national infrastructure in Ukraine, NATO and other countries perceived as hostile to Russian geopolitical interests. The US sanctioned both Pankratova and Degtyarenko in July 2024. The EU and the UK have since sanctioned Pankratova and Degtyarenko as of July 13, 2026.

According to industry reporting and a US-led technical advisory, CARR and Z-Pentest are at least linked to GRU Unit 74455 or The Main Center for Special Technologies (“GTsST”). US Rewards for Justice (RFJs) indicate that a malicious cyber actor known as “Cyber_1ce_Killer” is a member of CARR/Z-Pentest Alliance. The online persona “Cyber_1ce_Killer” is associated to at least one GRU officer.

The UK is concerned that the GRU has used Ukraine as a testing ground for the development of a range of cyber capabilities, integrated into its military doctrine, since 2014 onwards.

Russia’s destabilising activities are not commensurate with its role as a permanent member of the United Nations Security Council (UNSC). They also run contrary to the UN norms of responsible state behaviour in cyberspace, which Russia claims to uphold.

Geopolitical uncertainty, Russia’s intent and capability to target NATO allies and operational experience in Ukraine, provide the conditions for these threats to be redirected. It is imperative that the UK and our allies continue to support Ukraine and prepare for the potential redirection of GRU cyber and hybrid threats towards European partners, NATO allies and the United Kingdom now and in the future.

Together, through our work with NATO allies and the European Union, the UK will continue to raise awareness of the potential future threat scenarios which the GRU poses to us and our allies.