The number of cyber operations launched from Russia over the last few years is astounding, ranging from the NotPetya malware attack that cost the global economy billions, to the SolarWinds espionage campaign against dozens of US government agencies and thousands of companies. Broad characterizations of these operations, such as “Russian cyberattack,” obscure the very real and entangled web of cyber actors within Russia that receive varying degrees of support from, approval by, and involvement with the Russian government. This issue brief describes the large, complex, and often opaque network of cyber actors in Russia, from front companies to patriotic hackers to cybercriminals. It analyzes the range and ambiguity of the Russian government’s involvement with the different actors in this cyber web, as well as the risks and benefits the Kremlin perceives or gets from leveraging actors in this group. The issue brief concludes with three takeaways and actions for policymakers in the United States, as well as in allied and partner countries: focus on understanding the incentive structure for the different actors in Russia’s cyber web; specify the relationship any given Russian actor has or does not have with the state, and calibrate their responses accordingly; and examine these actors and activities from Moscow’s perspective when designing policies and predicting the Kremlin’s responses.
The number of cyber operations launched from Russia over the last few years is astounding, ranging from the NotPetya malware attack that cost the global economy billions to the SolarWinds espionage campaign against dozens of US government agencies and thousands of companies. Yet broad characterizations of these operations, such as “Russian cyberattack,” obscure the very real and entangled web of cyber actors within Russia that have varying degrees of support from, approval by, and involvement with the Russian government.
Contrary to popular belief, the Kremlin does not control every single cyber operation run out of Russia. Instead, the regime of President Vladimir Putin has to some extent inherited, and now actively cultivates, a complex web of Russian cyber actors. This network includes: cybercriminals who operate without state backing and inject money into the Russian economy; patriotic hackers and criminal groups recruited by the state on an ad hoc basis; and proxy organizations and front companies created solely for the purpose of conducting government operations, providing the Kremlin a veil of deniability. This web of cyber actors is large, often opaque, and central to how the Russian government organizes and conducts cyber operations, as well as how it develops cyber capabilities and recruits cyber personnel.
Referring to all cyber activities that take place inside of Russia as “Russian”—and even those launched from outside Russia by “Russian” actors—flattens the complexity of this network and undermines analysis of the range of actors at the Kremlin’s disposal. Likewise, assuming the Putin regime controls every single cyber activity emanating from Russia ignores the government’s spectrum of involvement with various actors and, in turn, the different opportunities the United States and its allies and partners may have to disrupt Moscow’s cultivation and use of this cyber ecosystem. While researchers continue to publish on the “cyber proxies” concept, proxy as a universal term fails to capture the gradations of the state’s involvement with hackers, assuming a top-down hierarchical relationship that is not always present in Russia. Public information this cyber ecosystem is not perfect or complete, but its relationship with the Russian government demands deeper analysis.
Untangling this multifaceted web—and understanding how and why so many Russian cyber actors freely operate in, and oscillate between, state and non-state domains—will allow the United States to appropriately target negotiations and track the expansion of Russian cyber operations globally. This is particularly important now, with the Putin regime facing an unprecedented level of sanctions from governments around the world, and the country’s information technology (IT) “brain drain” accelerating since the regime’s (re)invasion of Ukraine in February 2022. 1 Dina Temple-Raston and Sean Powers, “‘Cream of the Cream’: Russia’s High-Tech brain drain,” The Record , May 10, 2022, . Before these latest hostilities, the US government was negotiating a curtailment of ransomware attacks coming from within Russia; right after the war began, diplomatic talks between the Biden administration and the Kremlin quickly deteriorated. 2 See, for example: “U.S.–Moscow Ties Close to Rupture after Biden’s ‘War Criminal’ Remarks, Russia Says,” Reuters , March 21, 2022, . Arguably, understanding and disrupting Russian cyber operations in conflicts in Ukraine and other areas around the world is more important than ever for the US government and its allies and partners. However, the reality is that the US government cannot pursue these objectives effectively or comprehensively without first understanding and shaping its approach around the reality of Russia’s cyber ecosystem.
This four-part issue brief reviews the complex web of cyber actors in Russia, analyzes the range of Russian government involvement with these actors through specific examples, explains the risks and benefits the Kremlin perceives or gets from cultivating and leveraging this web of cyber actors, and provides three key takeaway-action pairings for US policymakers and its allies and partners.
Russia is to a convoluted web of cyber actors comprised of government-funded front companies, state-tapped individuals, cybercriminals, and “patriotic hackers,” among others. While some of these entities receive direct orders and financial support from Russian authorities, others have tacit permission to operate independently, so long as they do not upset the Putin regime. The Kremlin’s involvement with each of these actors follows a varied and ambiguous pattern of engagement that the section discusses in more detail. First, it is necessary to understand why the Russian government values this kind of cyberspace proxy activity, and how this activity has evolved into the convoluted and opaque web that exists in Russia today.
Political warfare is generally important to the Kremlin. The Putin regime, inside and beyond Russian borders, has carried out assassinations and attempted assassinations, funded propaganda front companies, spread disinformation, and launched disruptive cyber operations, among other activities. While the organizational structures that execute these activities, and the techniques used, vary, the goals are often similar: to disrupt, destroy, sabotage, and subvert enemies of the Russian state (read: enemies of the Putin regime) abroad and at . This reflects a growing emphasis in Russia’s military doctrine and national security thinking on the importance of information, proxy, and below-threshold-of-war conflict. 3 See, for example: Oscar Jonsson, The Russian Understanding of War: Blurring the Lines Between War and Peace (Washington, DC: Georgetown University Press, 2019). Russia’s 2000 Foreign Policy Concept stated that “while the [sic] military power still retains significance in relations among states, an ever greater role is being played by economic, political, scientific and technological, ecological, and information factors. 4 ”Russian Federation, 2000 Foreign Policy Concept of the Russian Federation , June 2000. Prominent Russian military theorists S. G. Chekinov and S. A. Bogdanov underscored this in their 2010 article that appeared in the Russian journal Military Thought , writing that “asymmetric actions, too, will be used extensively to level off the enemy’s superiority in an armed struggle by a combination of political, economic, information, technological, and ecological campaigns in the form of indirect actions and nonmilitary measures.” 5 S. G. Chekinov and S. A. Bogdanov, “The Nature and Content of a New-Generation War,” Military Thought ( Voyennaya Mysl’ ), no. 3 (2010): 12–23, 16, . Some of these political warfare actions, like disruptive cyber operations, explicitly target Russia’s enemies, while others have intentional indirect effects. Scholars Adrian Hänni and Miguel Grossmann, for instance, argue that the Putin regime’s “public, theatrical form of murderous attacks on intelligence defectors” is a kind of “signaling through covert action” to Russia’s enemies, Russian defectors, and the Russian public. 6 Adrian Hänni and Miguel Grossmann, “Death to Traitors? The Pursuit of Intelligence Defectors from the Soviet Union to the Putin Era,” Intelligence and National Security 35, no. 3 (2020): 403–423, 404, 407.
Russia is to a convoluted web of cyber actors comprised of government-funded front companies, state-tapped individuals, cybercriminals, and “patriotic hackers,” among others.”
Political warfare is generally important to the Kremlin. The Putin regime, inside and beyond Russian borders, has carried out assassinations and attempted assassinations, funded propaganda front companies, spread disinformation, and launched disruptive cyber operations, among other activities. While the organizational structures that execute these activities, and the techniques used, vary, the goals are often similar: to disrupt, destroy, sabotage, and subvert enemies of the Russian state (read: enemies of the Putin regime) abroad and at . This reflects a growing emphasis in Russia’s military doctrine and national security thinking on the importance of information, proxy, and below-threshold-of-war conflict. 7 See, for example: Oscar Jonsson, The Russian Understanding of War: Blurring the Lines Between War and Peace (Washington, DC: Georgetown University Press, 2019). Russia’s 2000 Foreign Policy Concept stated that “while the [sic] military power still retains significance in relations among states, an ever greater role is being played by economic, political, scientific and technological, ecological, and information factors.” 8 Russian Federation, 2000 Foreign Policy Concept of the Russian Federation , June 2000. Prominent Russian military theorists S. G. Chekinov and S. A. Bogdanov underscored this in their 2010 article that appeared in the Russian journal Military Thought , writing that “asymmetric actions, too, will be used extensively to level off the enemy’s superiority in an armed struggle by a combination of political, economic, information, technological, and ecological campaigns in the form of indirect actions and nonmilitary measures.” 9 S. G. Chekinov and S. A. Bogdanov, “The Nature and Content of a New-Generation War,” Military Thought ( Voyennaya Mysl’ ), no. 3 (2010): 12–23, 16, . Some of these political warfare actions, like disruptive cyber operations, explicitly target Russia’s enemies, while others have intentional indirect effects. Scholars Adrian Hänni and Miguel Grossmann, for instance, argue that the Putin regime’s “public, theatrical form of murderous attacks on intelligence defectors” is a kind of “signaling through covert action” to Russia’s enemies, Russian defectors, and the Russian public. 10 Adrian Hänni and Miguel Grossmann, “Death to Traitors? The Pursuit of Intelligence Defectors from the Soviet Union to the Putin Era,” Intelligence and National Security 35, no. 3 (2020): 403–423, 404, 407.
This assessment has its roots in historical actions, bureaucracy, and thinking that inform how Moscow uses cyber and information capabilities today. The Soviet Union conducted political warfare-style operations under an umbrella of “active measures” against foreign and domestic targets. Akin to contemporary political warfare, these actions ranged from assassinating émigré leaders who participated in anti-Soviet activities to manufacturing and spreading the lie that the Pentagon started the AIDS epidemic. 11 See, for example: US Central Intelligence Agency, Soviet Use of Assassination and Kidnapping , Declassified, 1964, 1, Mark Kramer, “Lessons From Operation ‘Denver,’ the KGB’s Massive AIDS Disinformation Campaign,” MIT Press Reader , May 26, 2020, . Of course, the parallels are not perfect, and the information environment today is fundamentally different than it was decades ago. For example, the scale and speed of microtargeting alone, enabled by the internet, is unprecedented. Regardless, the Putin regime and the Russian security apparatus continue to emphasize many of the same Soviet-era, active measures-type ideas, such as deniability, covertness, and the use of proxies, which carries over to cyber operations. 12 Justin Sherman, “Digital Active Measures: Historical Roots of Contemporary Russian Cyber and Information Operations,” Georgetown Security Studies Review 9, no. 2 (Washington, DC: Georgetown University’s Edmund A. Walsh School of Foreign Service, April 2022): 1–9, . Russia’s modern structure for information operations reportedly even mirrors the Soviet approach; after the collapse of the Soviet Union, the military transferred its propaganda directorate to the military intelligence agency ( Glavnoye Razvedyvatelnoye Upravlenie , or GRU), rebranding it GRU Unit 54777 in 1994. 13 Andrei Soldatov and Michael Weiss, “Inside Russia’s Secret Propaganda Unit,” Newsline Magazine , December 7, 2020, . This unit still exists today and, 14 See, for example: Antonin Toianovski and Ellen Nakashima, “How Russia’s Military Intelligence Agency Became the Covert Muscle in Putin’s Duels with the West,” Washington Post , December 28, 2018, . per the US Department of the Treasury’s 2021 sanctions, falls under Russia’s Information Operations Troops. 15 To the reader, GRU Unit 54777 is also known as the 72nd Main Intelligence Information Center (GRITs), which the US Treasury Department identified as belonging to Russia’s Information Operations Troops. US Department of the Treasury, “Treasury Escalates Sanctions Against the Russian Government’s Attempts to Influence U.S. Elections,” April 15, 2021, . From strategic thinking to operational style to intelligence structure and culture, many similarities exist between the active measures of the Soviet Union and the political warfare activities of contemporary Russia.
To some extent the Putin regime inherited this convoluted web of cyber actors. Economic decline and political instability following the demise of the Soviet Union contributed to an explosion of crime, 16 See, for example: Mark Galeotti, “Gangster’s Paradise: How Organized Crime Took Over Russia,” The Guardian , March 23, 2018, ; Vsevolod Sokolov, “From Guns to Briefcases: The Evolution of Russian Organized Crime,” World Policy Journal 21, no. 1 (Spring 2004): 68–74, . including cybercriminal activity. Among other reasons, a lack of laws and enforcement related to cybercrime, limited economic opportunities, and “highly educated and technologically empowered segments of [the] population with the capability to conduct sophisticated criminal operations” all accelerated the pace of cybercrime in 1990s Russia. 17 Dmitri Alperovitch and Keith Mularski, “Fighting Russian Cybercrime Mobsters: Report from the Trenches,” BlackHat, July 25–30, 2009, 2, . This activity evolved from software piracy to more serious forms of profit generation like hacking banks and stealing identities. 18 Lucie Kadlecová, “Russian-Speaking Cyber Crime: Reasons Behind Its Success,” The European Review of Organized Crime 2, no. 2 (2015): 104–121, 4, . By the time Putin ascended to the presidency in December 1999, there were already numerous nonstate hackers in Russia engaged in criminal behavior.
Instead of cracking down, the Kremlin actively cultivated this network of cyber actors, and continues to leverage this ecosystem for purposes that extend beyond criminal activity. The Putin regime allows cybercriminals and patriotic hackers to operate freely within Russia, so long as they focus on foreign targets, do not undermine the Kremlin’s objectives, and answer to the state when asked. The Federal Security Service (FSB), Russia’s internal security agency with some foreign purview, recruits cybercriminals to carry out operations on its behalf. The Foreign Intelligence Service (SVR) sets up front organizations to conduct cyber and information operations against foreign targets. The Kremlin permits private military companies (PMCs) to operate around the world and to sell their military and protective services to foreign governments; at least one Russian PMC has developed a cyber unit. 19 Emma Schroeder et. al, Hackers, Hoodies, and Helmets: Technology and the Changing Face of Russian Private Military Contractors, Atlantic Council , July 2022 , 5 20 , . While Putin did inherit an ecosystem of both legitimate technology companies and technically talented individuals engaged in cybercrime, the regime has purposefully shaped this resource pool of Russian cyber actors to its own benefit, though not without accompanying risks.
It is worth noting that this issue brief focuses primarily on cyber operations as understood by the United States (pertaining to code) but also mentions information operations throughout (pertaining to, in the US view, human-readable content). Russia’s conceptualization of the information space does not make such a firm distinction. Therefore, this issue brief errs toward depicting the Russian understanding of the space, as well as highlighting some of the similarities between the ways Russian actors have conducted cyber and information operations, such as the government setting up cyber and information front organizations in other countries.
Putin does not control every single cyber operation that occurs within or comes out of Russia. In fact, as Candace Rondeaux writes, the “narrative of a grand chess master, whether Putin, a Kremlin insider, or a mercenary group, singlehandedly orchestrating Russia’s proxy warfare strategy is a useful fiction for the Kremlin.” 21 Candace Rondeaux, Decoding the Wagner Group: Analyzing the Role of Private Military Security Contractors in Russian Proxy Warfare, New America , November 7, 2019, 8, . Simply put, “Vladimir Putin is not omnipotent,” as journalist Julia Ioffe remarked in 2013. 22 Julia Ioffe, “Dear Lawrence O’Donnell, Don’t Mansplain to Me Russia,” The New Republic , August 8, 2013, . In reality, there are degrees of Russian government involvement with most Russian cyber actors, whether it is through active financing, tacit approval, or another kind of engagement entirely. It is also possible that some activity is entrepreneurial by design, with nonstate hackers and developers auditioning their capabilities to capture the attention of the state. 23 Thanks to Gavin Wilde for discussion of this point. Further, for all that Russian doctrines and military thinking emphasize the importance of political warfare and cyber and information operations, there is a great deal of complexity, competition, and internal conflict in how the Russian government bureaucracy attempts to operationalize those doctrines and ideas. Unpacking this spectrum of Russian government involvement with hackers is essential for the United States and its allies and partners to accurately analyze the Russian cyber web, as well as to identify areas to disrupt Russian government or government-directed activity.
In 2011, Jason Healey described a spectrum of state involvement in cyber activity, 24 Jason Healey, “The Spectrum of National Responsibility for Cyberattacks,” The Brown Journal of World Affairs 18, no. 1 (Fall/Winter 2011): 57–70, . identifying ten separate types of hacking: state-prohibited, state-prohibited-but-inadequate, state-ignored, state-encouraged, state-shaped, state-coordinated, state-ordered, state-rogue-conducted, state-executed, and state-integrated. 25 Jason Healey, Beyond Attribution: Seeking National Responsibility in Cyberspace , Atlantic Council , February 22, 2012, 2, . While Healey’s intention was to enhance the conversation around government responsibility for cyber operations beyond technical attribution, his framework alone illustrates that governments can maintain a range of relationships with hackers to suit their purposes. Putin’s regime has taken—and continues to take—this exact approach.
The extensive Russian network includes: internal government cyber and information units; front companies established and run by the government; private companies leveraged by the government to develop capabilities and recruit talent; criminals recruited by state officials; industry developers recruited by state officials; independently operating patriotic hackers (often with state encouragement or as cover for state-run action); hackers independently building their capabilities and pitching them to the state; and murky, mafia-style familial entanglements between hackers and Russian government officials. Experts have published excellent research on cyber proxies, 26 See, for example: Healey, Beyond Attribution ; Tim Maurer, Cyber Mercenaries: The Stater, Hackers, and Power (Cambridge: Cambridge University Press, 2017); Erica D. Borghard and Shawn W. Lonergan, “Can States Calculate the Risks of Using Cyber Proxies?” Orbis 60, no. 3 (2016): 395–416. yet, in Russia’s case, questions remain the exact nature of those relationships, as they sometimes defy the frequent assumption that proxy activity refers to a top-down hierarchical relationship, with the state as the primary actor. Considerable portions of Russia’s cybercriminal ecosystem operate with a sort of Darwinian entrepreneurialism, akin to the approach of Russian criminal enterprises and protective services in the 1990s.Thanks to several individuals for discussion of this point. 27 See, for example: Vadim Volkov, Violent Entrepreneurs: The Use of Force in the Making of Russian Capitalism (Ithaca: Cornell University Press, 2002). Criminals often have substantial agency to drive this activity. And when there are quasi-symbiotic relationships at play with the state—a local FSB official, for instance, taking money on the side to provide a “roof” ( krysha ) of protection for hackers—these relationships do not entirely follow top-down or state-dominated definitions. It is also important to note, before diving into examples of actors in the Russian cyber web, that each case study raises questions replicability. 28 Thanks to a workshop participant for discussion of this point. Some examples may be entirely or somewhat replicable, while others could be one-off cases, shaped by factors such as the Russian government’s operational needs, budgetary resources, technical constraints, and others.
The Russian government has many internal teams carrying out cyber operations. The FSB, GRU, and SVR all have cyber units, in addition to the cyber organizations located within other parts of the Russian military and security service apparatus. 29 For a recently published discussion of the Russian government’s cyber units, see: Andrei Soldatov and Irina Borogan, Russian Cyberwarfare: Unpacking the Kremlin’s Capabilities (Washington, D.C.: Center for European Policy Analysis, . For example, the FSB’s 16th Center has signals intelligence capabilities, and its 18th Center has been responsible for hacks of Yahoo, Ukrainian targets, and others. 30 US Library of Congress, Congressional Research Service, Russian Cyber Units , by Andrew S. Bowen, IF11718 (2022), 2, ; “Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine,” Palo Alto Networks, February 3, 2022 (updated June 22, 2022), . The GRU has multiple cyber teams, including Unit 26165 (“Fancy Bear”), 31 See, for example: “Investigative Report: On The Trail Of The 12 Indicted Russian Intelligence Officers,” RadioFreeEurope/RadioLiberty , July 19, 2018, . that carried out the 2016 hack of the Democratic National Committee, 32 US Department of Justice, “Grand Jury Indicts 12 Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election,” July 13, 2018, . and Unit 74455 (“Sandworm”), that hacked power grids in Ukraine. 33 See, for example: Andy Greenberg, “Russia’s Sandworm Hackers Attempted a Third Blackout in Ukraine,” WIRED , April 12, 2022, ; Andy Greenberg, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin’s Most Dangerous Hackers (New York: Penguin Random House, 2020). Even though less is known its internal cyber structure, 34 Thanks to individuals who participated in a Chatham House Rule workshop on Russian cyber operations for discussion of this issue. the SVR has also carried out major operations, such as the SolarWinds hack in 2020. 35 See, for example: US Cybersecurity & Infrastructure Security Agency (CISA), “Russian Foreign Intelligence Service (SVR) Cyber Operations: Trends and Best Practices for Network Defenders,” April 26, 2021, . Often these operations are launched from within Russia, but at other times, state hackers have gone abroad to attack targets. In 2018, for example, operatives from GRU Unit 26165 traveled to the Netherlands to hack into and disrupt the investigation of the Organization for the Prohibition of Chemical Weapons (OPCW) into the poisoning of Sergei Skripal and his daughter. 36 “How the Dutch Foiled Russian ‘Cyber-Attack’ on OPCW,” BBC, October 4, 2018, . GRU Unit 26165 hackers, apparently part of the same sub-team of GRU Unit 26165, were also on site in Rio de Janeiro, Brazil and Lausanne, Switzerland to break into systems of the US Anti-Doping Agency, the World Anti-Doping Agency, and the Canadian Center for Ethics in Sport. 37 United States of America vs. Aleksei Sergeyevich Morenets , et al. (2018), 6, .
Moscow finances and directs cyber and information operations through front organizations and websites used by the GRU, the SVR, and the FSB to spread disinformation. 38 US Department of the Treasury, “Treasury Escalates Sanctions Against the Russian Government’s Attempts to Influence U.S. Elections.” The Russian government also uses companies like Neobit and AST to technically support cyber and information operations, with some companies acting like contractors but in a covert capacity. 39 US Department of the Treasury, “Treasury Sanctions Russia with Sweeping New Sanctions Authority,” April 15, 2021, . It is possible that the Russian government is increasingly stationing these cyber and information assets overseas. One of the Russian spies the United States caught and deported in June 2010 was working at Microsoft. The man had no apparent links to the Russian intelligence community. However, federal authorities knew that he had previously worked at Neobit, 40 Benjamin Carlson, “Who Was the 12th Russian Spy at Microsoft?” The Atlantic , July 14, 2010, ; Sébastian Seibt, “Microsoft Entangled in Russian Spy Scandal,” France24 , July 15, 2010, . currently linked, per the US Department of the Treasury’s April 2021 sanctions, to the Russian Ministry of Defense, the FSB, and the SVR. 41 US Department of the Treasury, “Treasury Sanctions Russia with Sweeping New Sanctions Authority.” In 2019, a Czech magazine reported that the Czech Security Information Service had shut down two private IT companies in early 2018 that were fronts for Russian hackers, reportedly part of a broader international network. 42 “Czech Intel Reveals Russian Hackers Using IT Company Front: Media,” UNIAN Information Agency, March 19, 2019, . Outside of what the United States considers cyber operations, but well within the Russian government’s cohesive conception of the information space, the Internet Research Agency has since 2016 been setting up overseas offices in Ghana, Nigeria, and Mexico to covertly run information operations. 43 Clarissa Ward et. al, “Russian Election Meddling Is Back – via Ghana and Nigeria – and in Your Feeds,” CNN, April 11, 2020, ; US Office of the Director of National Intelligence, Foreign Threats to the 2020 US Federal Elections , March 2021, 4, . Yevgeny Prigozhin, Putin’s “chef” and confidante, heads these operations that, even while coordinated surreptitiously by the Kremlin, may not involve constant or direct government control.
The Russian government also recruits hackers and cybercriminals on an ad hoc basis to conduct operations. 44 To the reader, as part of the broader Kremlin recruitment of criminals, see: Mark Galeotti, Crimintern: How the Kremlin Uses Russia’s Criminal Networks in Europe (Berlin: European Council on Foreign Relations, April 2017), . Authorities allow the Russian cybercriminal apparatus to thrive for a variety of reasons, including the fact that cybercrime brings money into Russia, and the talent base it cultivates gives the Kremlin proxies to tap as needed. It is also part and parcel of the pervasive corruption in the Russian business and government world. Through the “social contract” these hackers have with the Kremlin, they generally get permission to operate freely, as long as they focus mainly on foreign targets and do not undermine the Kremlin’s objectives. They must also be responsive to Russian government requests, even if the motives of these cybercriminals are primarily financial. 45 See, for example: Raymond Pompon recounting Russian cybercriminals complaining the prospect of being coopted by the security services: Raymond Pompon, “Russian Hackers, Face to Face,” F5, August 1, 2017, . (In the rare, publicly reported instances of Russian authorities arresting cybercriminals, the hackers involved had either stolen from or targeted Russian citizens. 46 See, for example: “Russian hacker gang arrested over $25m theft,” BBC, June 2, 2016, ; Jeff Stone, “Rare Cybercrime Enforcement in Russia Yields 25 Arrests, Shutters ‘BuyBest’ Marketplace,” CyberScoop , March 25, 2020, ; Roman Zakharov, “Detentions in the Case of the Largest Group of Hackers Took Place in 11 Regions of the Russian Federation,” Задержания по делу крупнейшей группировки хакеров прошли в 11 регионах РФ, TV Zvevda , March 24, 2020, . Even former FSB-linked hackers may not be safe if they violate the Kremlin’s social contract. 47 “Russian Hackers Allegedly Tied to FSB and Hack of U.S. Democratic Party Handed Lengthy Prison Terms,” RadioFreeEurope/RadioLiberty , February 14, 2022, . ) As Nina Kollars and Michael Petersen write, “institutional boundaries have become porous, allowing private citizens and organizations to conduct sanctioned state activities and allowing the state to mine society for autonomous assets to carry out state functions.” 48 Nina A. Kollars and Michael B. Petersen, “Feed the Bears, Starve the Trolls: Demystifying Russia’s Cybered Information Confrontation Strategy,” The Cyber Defense Review (2019): 145–158, 148 .
Several cases underscore how the Russian government recruits programmers and criminal hackers as needed, often through the FSB. In the late 2000s, the FSB reportedly contacted an individual tied to a patriotic hacker website in an attempt to establish a cooperative relationship. 49 “It’s Our Time to Serve the Motherland,” Meduza, August 7, 2018, ; Andrei Soldatov, “Cyber Surprise,” Кибер-сюрприз, Novaya Gazeta , May 30, 2007, . Around the time of the Russo-Georgian War in 2008, Russian intelligence agencies tried to create an online forum to recruit hackers to attack Georgian targets. 50 Insikt Group, “Dark Covenant: Connections Between the Russian State and Criminal Actors,” (Somerville: Recorded Future, September 2021), 4, . In September 2015, the independent Russian news website Meduza reported that Alexander Vyarya, who worked at a Russian company building distributed denial-of-service (DDoS) defense software, said Rostec, Russia’s defense conglomerate, approached him requesting his help to improve the government’s DDoS attack capabilities. 51 Daniel Turovsky, “Why Did the State Corporation Need a System for Organizing DDoS Attacks,” Грузить по полной программе, Meduza, September 3, 2015, ; Freid Weir, “In Russia’s Cyberscene: Kremlin Desires, Private Hackers, and Patriotism,” The Christian Science Monitor , October 27, 2016, . Vyarya noted that, at a meeting in Sofia, Bulgaria, software developers showed him an existing Russian government DDoS capability, which was demonstrated on the websites of the Ukrainian Ministry of Defense and the Russian edition of Slon.ru (an online magazine); 52 Turovsky, “Why Did the State”; Weir, “In Russia’s Cyberscene.” Vyarya refused to get involved and then left Russia. 53 Turovsky, “Why Did the State”; Weir, “In Russia’s Cyberscene.” This last example illustrates an additional set of risks and incentives—those of individuals working as company programmers tapped by the Russian government to provide assistance who must assess the consequences of refusal.
In 2017, the US Department of Justice charged two FSB officers and their criminal collaborators with hacking into Yahoo and millions of email accounts. 54 US Department of Justice, “U.S. Charges Russian FSB Officers and Their Criminal Conspirators for Hacking Yahoo and Millions of Email Accounts,” Justice.gov, March 15, 2017, . The indictment alleged that the officers “conspired together and with each other to protect, direct, facilitate, and pay criminal hackers to collect information through computer intrusions in the US and elsewhere.” 55 United States of America v. Dmitry Dokuchaev , Igor Sushchin, Alexsey Belan, and Karim Baratov , CR17-109 (2017), 2, . The document stated that the officers tasked hackers with targeting Yahoo email accounts; when they wanted information from non-Yahoo emails, they tasked a hacker and paid them a “bounty.” 56 United States of America v. D. Dokuchaev et al., 3. The indictment described one officer, in particular, as a hacker’s “handling FSB officer.” 57 United States of America v. D. Dokuchaev et al., 3. Yet these FSB officers went a step beyond material direction and financing. In line with other nominally state-sanctioned criminal activities in Russia, the FSB officers allegedly provided one of the hackers with “sensitive FSB law enforcement and intelligence information that would have helped him avoid detection by law enforcement, including information regarding FSB investigations of computer hacking and FSB techniques for identifying criminal hackers.” 58 United States of America v. D. Dokuchaev et al ., 2–3.
Other accounts describe parts of the Russian government, including the FSB, the GRU, and the Ministry of Internal Affairs, cultivating close relationships with nonstate hackers. 59 See, for example: Insikt Group, “Dark Covenant”; Joe Cheravitch and Bilyana Lilly, “Russia’s Cyber Limitations in Personnel Recruitment and Innovation, Their Potential Impact on Future Operations and How NATO and Its Members Can Respond,” NATO Cooperative Cyber Defense Center of Excellence, December 2020, , 31–59: 38–39; Flashpoint, “Russia Is Cracking Down on Cybercrime. Here Are the Law Enforcement Bodies Leading the Way,” February 14, 2022, ; United States of America vs. Yevgeniy Alexandrovich Nikulin , CR 16-00440 WHA (2020), United States’ Motion in Limine No. Six to Exclude Hearsay Statements by Nikita Kislitsin, 4, . Positive Technologies, a Russian IT firm sanctioned by the US government, hosts conventions that the FSB and the GRU use as recruiting events. 60 US Department of the Treasury, “Treasury Sanctions Russia with Sweeping New Sanctions Authority.” The US Treasury Department stated in April 2021 that the FSB cultivated and coopted the ransomware group Evil Corp. 61 US Department of the Treasury, “Treasury Sanctions Russia with Sweeping New Sanctions Authority.” The FSB had apparently given one of Evil Corp’s alleged members, Igor Turashev, enough cover to register three Russian companies in his name, in a building known for crypto firm money laundering. 62 Joe Tidy, “Evil Corp: ‘My hunt for the World’s Most Wanted Hackers,’” BBC, November 17, 2021, ; Kartikay Mehrotra and Olga Kharif, “Ransomware HQ: Moscow’s Tallest Tower Is a Cybercriminal Cash Machine,” Bloomberg , November 3, 2021, . Despite this apparent brazenness, most nonstate hacker recruitment occurs in the more obscure corners of the Russian cyber web. As journalist and Russian intelligence expert Andrei Soldatov has said, “We know there is a huge pool of capable talent, and at least some people who are willing to do things that are suggested to them. We know such things are being done. What we don’t know is how or why such orders are formulated, and who exactly may be involved.” 63 Weir, “In Russia’s Cyberscene.” To Soldatov’s point, different elements of the Russian security apparatus may tap hackers for different purposes, ranging from strategic to highly tactical; nonstate hacker recruitment does not necessarily originate from the same level of the Russian government.
Beyond the outright backing and recruitment of nonstate cyber actors, the Kremlin also engages in other target activities, such as encouraging individuals to carry out cyber operations. Patriotic hacking groups are a prime example. These collectives, ranging from loosely to more formally organized, are composed of technically skilled people who conduct operations in line with government interests (or what they perceive as government interests). Some of these activities began with a domestic bent, such as the policing and targeting of regime critics online, 64 See, for example: Françoise Daucé, Benjamin Loveluck, Bella Ostromooukhova, and Anna Zaytseva, “From Citizen Investigators to Cyber Patrols: Volunteer Internet Regulation in Russia,” Russian Review of Social Research 11, no. 3 (2019): 46–70; “Nashi Denies Cyberattack on Kommersant, Threatens Lawsuit,” Moscow Times , February 9, 2012, . See also, on the Internet Research Agency: Adrian Chen, “The Agency,” New York Times Magazine , June 2, 2015, . but have since expanded into the foreign arena. Following the Russia-originating cyber operations against Estonia in 2007, a representative of the Unified Russia party said his assistant—a member of the pro-Kremlin youth group Nashi—participated in the attacks. 65 Chloe Arnold, “Russian Group’s Claims Reopen Debate On Estonian Cyberattacks,” RadioFreeEurope/RadioLiberty , March 30, 2009, . On patriotic hacking, see also: Dorothy Denning, “Tracing the Sources of Today’s Russian Cyberthreat,” Scientific American , August 18, 2017, . During the 2008 Russo–Georgian War, it appears patriotic hackers may have taken part in launching DDoS attacks against Georgian websites. 66 Stephen W. Korns and Joshua E. Kastenberg, “Georgia’s Cyber Left Hook,” Parameters 38, no. 4 (Winter 2008–2009), . See also, on the Russian Business Network criminal group some suspected was involved: Peter Warren, “Hunt for Russia’s Web Criminals,” The Guardian , November 15, 2007, .
These individuals genuinely believe they are expressing patriotism for the Russian nation. An analysis of pro-Russian and pro-Ukrainian patriotic hacker Twitter posts between 2014 and 2017, after the Putin regime’s invasion and annexation of Crimea, found that the hackers created a “popular, even populist identity” online based on patriotism. 67 Tetyana Lokot, “Public Networked Discourses in the Ukraine-Russia Conflict: ‘Patriotic Hackers’ and Digital Populism,” Irish Studies in International Affairs 28 (2017): 99–116, 113, . In 2007, malicious web queries transmitted to Estonian websites by Russian actors (believed to be patriotic hackers) invoked false claims of fascism in reference to Andrus Ansip, Estonia’s then-prime minister, with phrases such as “ANSIP_PIDOR=FASCIST,” 68 Rain Ottis, “Analysis of the 2007 Cyber Attacks Against Estonia from the Information Warfare Perspective,” NATO Cooperative Cyber Defense Center of Excellence, 2008, 2, . echoing a nationalistic narrative espoused by members of the Russian parliament. 69 Luke Harding, “Russia up in arms after Estonians remove statue of Soviet soldier,” The Guardian , April 27, 2007, .
Meduza reports that several Russian-speaking, nonstate hackers identified the 2008 Russo–Georgian War as a catalyst for Russian intelligence service recruitment of patriotic hackers. 70 Meduza, “It’s Our Time to Serve the Motherland.” There has recently been speculation the Russian government encouraging the patriotic hacking of Ukrainian targets. 71 See, for example: Joe Tidy, “Russian Vigilante Hacker: ‘I Want to Help Beat Ukraine from My Computer,’” BBC, February 25, 2022, . Yet, hacks of this kind are not always state-directed. Something as simple as a Kremlin official getting on TV and criticizing a foreign country might be the only prompt a patriotic hacker needs to act. After browsing online forums that shared software for possible use to attack Georgia, journalist Evgeny Morozov said in August 2008:
In less than an hour, I had become an internet solider. I didn’t receive any calls from Kremlin operatives; nor did I have to buy a web server or modify my computer in any significant way.…Paranoid that the Kremlin’s hand is everywhere, we risk underestimating the great patriotic rage of many ordinary Russians, who, having been fed too much government propaganda in the last few days, are convinced that they need to crash Georgian websites. 72 “Evgeny Morozov, “An Army of Ones and Zeros,” SlateMagazine , August 14, 2008, .
Speculation also exists that the Russian government encourages patriotic hacking to provide cover for state-run operations.
Although these individuals and organizations have permission to operate independently, Moscow does not hide its affinity for these hackers or their cyber capabilities. In a June 2017 meeting with international media, Putin compared patriotic hackers to painters, saying that “hackers are free people. They are like artists. If they are in a good mood, they get up in the morning and begin painting their pictures.” 73 “Putin Compares Hackers To ‘Artists,’ Says They Could Target Russia’s Critics For ‘Patriotic’ Reasons,” RadioFreeEurope/RadioLiberty , June 1, 2017, . He elaborated that “hackers are the same. They wake up in the morning, they read some developments in international affairs, and if they have a patriotic mindset, then they try to make their own contribution the way they consider right into the fight against those who have bad things to say Russia.” 74 “Putin Compares Hackers To ‘Artists,’” RadioFreeEurope/RadioLiberty . Explicitly directed or not, Putin is well aware that patriotic hackers are a component of the Russian cyber web that the government can leverage at will.
Otherwise, most Russian state involvement with nonstate hackers is ill-defined. The Russian hacking group Evil Corp, indicted by the United States in November 2019 and sanctioned that December, is an illustrative example. 75 United States of America vs. Maskim V. Yakubets and Igor Turashev , CR 19-342 (W.D. Pa., 2019), ; US Department of the Treasury, “Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware,” December 5, 2019, . The group is run by Maxim Yakubets, a Russian hacker reportedly married to Alyona Eduardovna Benderskaya, the daughter of Eduard Bendersky. 76 “The FSB’s Personal Hackers,” Meduza, December 12, 2019, ; Mark Krutov and Sergey Dobrynin, “Son in Law for 5 Million,” Зять на 5 миллионов, Svoboda , December 9, 2019, . A former FSB Spetsnaz officer, Bendersky owns multiple private Russian security firms and, according to Bellingcat , is a “de-facto spokesman for Department V” or Vympel, 77 “‘V’ for ‘Vympel’: FSB’s Secretive Department ‘V’ Behind Assassination Of Georgian Asylum Seeker in Germany,” Bellingcat , February 17, 2020, . the FSB’s externally focused “antiterrorist” unit that has carried out multiple overseas assassinations. 78 US Library of Congress, Russian Military Intelligence: Background and Issues for Congress , by Andrew S. Bowen, R46616, Congressional Research Service, November 2021, 13 ; “‘V’ for ‘Vympel’”; “FSB’s Magnificent Seven: New Links between Berlin and Istanbul Assassinations,” Bellingcat , June 29, 2020, . Since 2017, the year he and Bendersky’s daughter presumably married, Yakubets 79 US Department of the Treasury, “Treasury Sanctions Evil Corp.” Yakubets has been in the process of getting a Russian government security clearance since April 2018 80 Meduza, “The FSB’s personal hackers”; US Department of the Treasury, “Treasury Sanctions Evil Corp.” He is still at large in Russia, despite alleged Russian arrests of affiliates of a different ransomware group, REvil, in February 2022 81 Arielle Waldman, “Fallout from REvil arrests shakes up ransomware landscape,” TechTarget, February 14, 2022, . that had provided a glimmer of (wishful) hope that Moscow was, in fact, actually cracking down on ransomware and other cybercriminal activity. One senior US official, for example, had—quite idealistically—told reporters following the REvil arrests that “these are very important steps, in that they represent the Kremlin taking action against criminals operating from within its borders, and they represent what we’re looking for with regard to continued activities like these in the future.” 82 James Rundle, Catherine Stupp, and Kim S. Nash, “What Russia’s Arrest of REvil Hackers Means for Ransomware,” Wall Street Journal , January 14, 2022, .
[Hackers] wake up in the morning, they read some developments in international affairs, and if they have a patriotic mindset, then they try to make their own contribution the way they consider right into the fight against those who have bad things to say Russia.”
Putin does not control all these groups, and even if the FSB does engage with a hacker on a local level, Putin is (by and large) not involved in the day-to-day minutiae. Nevertheless, the Kremlin clearly allows cybercriminals and other nonstate hackers to thrive in Russia. Moreover, for the largest groups in the cyber web, the regime to a certain extent actively decides to look the other way. Given these circumstances, the section discusses the benefits the regime gets, or perceives it gets, from leveraging this network of Russian cyber actors.
From the Kremlin’s perspective, the web of Russian cyber actors—from nonstate patriotic hackers and cybercriminals to state-funded front companies—can provide numerous benefits. Principally, the returns include deniability, the power to wage covert political warfare below the threshold of outright war, and potentially reduced costs to maintain cyber capabilities. Additionally, the economic benefits should not be downplayed. While exact figures are hard to come by, cybercriminals are clearly bringing money into Russia, with billions of dollars estimated to have been raked in already by 2014. 83 Tim Maurer, Why the Russian Government Turns a Blind Eye to Cybercriminals , Carnegie Endowment for International Peace , February 2, 2018, . In 2021 alone, it was reported that 74 percent of global ransomware revenue went to Russian hackers, to the tune of $400 million in cryptocurrencies. 84 Joe Tidy, “74% of Ransomware Revenue Goes to Russia-Linked Hackers,” BBC, February 14, 2022, . That said, this activity also comes with many risks, including having to deal with competence and discipline issues that contribute to political-criminal tensions within hacking groups, undermining effectiveness. Recruiting from overlapping groups can also lead to political problems when the hackers act outside their remit or no longer work for the state but are identified as state actors. There is a simultaneous interplay between all these dynamics.
As noted, deniability is a pivotal factor in the Kremlin’s strategic and operational decision-making. Putin is not a micromanager. 85 Fiona Hill and Clifford G. Gaddy, What Makes Putin Tick, and What the West Should Do , Brookings Institution , January 13, 2017, . Instead, he operates an “adhocracy” that allows elites to “become policy entrepreneurs, seeking and seizing opportunities to develop and even implement ideas that they think will further the Kremlin’s goals.” 86 Mark Galeotti, “Russia Has No Grand Plans, but Lots of ‘Adhocrats,’” Intellinews , January 18, 2017, . See also: Mark Galeotti, “Russia’s Murderous Adhocracy,” Moscow Times , August 22, 2020, . Thanks as well to Brian Whitmore for discussion of this point during the writing of my Reassessing RuNet report. In practice, this creates ambiguity and, from the Kremlin’s perspective, plausible deniability. 87 Lucian Kim, “In Putin’s Russia, An ‘Adhocracy’ Marked By Ambiguity And Plausible Deniability,” NPR, July 21, 2017, . This approach is particularly conducive to cyber and information operations because they can be conducted remotely from behind a computer screen. Some argue that this deniability is implausible, correctly pointing out that Moscow often poorly obscures links between Kremlin officials and supposedly non-state-affiliated proxies, 88 See, for example: Paul Stronski, Implausible Deniability: Russia’s Private Military Companies , Carnegie Endowment for International Peace , June 2, 2020, . such as in the case of the patriotic hackers targeting Estonia, Georgia, and Ukraine. In some instances, Russian officials blatantly lie, even when faced with overwhelming evidence to the contrary. In 2018, when Dutch intelligence caught and publicly exposed the GRU Unit 26165 operatives who flew to The Hague to disrupt the OPCW investigations, one retired Russian lieutenant general said, “You say this is evidence. It’s not evidence to me. Russian intelligence was believed to be among the best in the world. Now you want to present a bunch of fools, absolutely incompetent, absolutely stupid, non-professional idiots? It’s insulting.” 89 Sarah Rainsford, “Have Russian Spies Lost Their Touch?” BBC, October 6, 2018, .
Regardless, the Kremlin does have periods when it can deny knowledge of, association with, and/or responsibility for cyber and information activities. While the ongoing war in Ukraine is an example of (Western) government intelligence exposing Russian plans and act...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
