CSIDB logo
Threat actor

GRU-backed hackers

Attribution profile

Type
Nation State
Location
Russia
Known incidents
2 incidents
First seen
2017-06-01
Last seen
2022-11-29
Updated
2026-08-01 02:14
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly described as GRU‑backed hackers, also referred to as Hackers rusos, and is linked to the Russian state’s Main Directorate of the General Staff (GRU). Attribution to Russia is explicitly stated in the reporting, with the actors characterized as Russia‑backed and tied to the Kremlin’s intelligence agency. Their known activity has focused on two primary sectors: telecommunications and energy. In the telecommunications case, the actor targeted Argentina’s state‑owned satellite provider ARSAT, attempting to breach internal corporate systems while avoiding customer‑facing infrastructure. In the energy case, the actor focused on the Republic of Ireland’s Electricity Supply Board (ESB), seeking to reach senior engineers with the aim of accessing energy network control systems that could affect power supplies in Northern Ireland. The reported objectives therefore involve intelligence gathering through surveillance of organizational practices and the potential to cause disruption, although no confirmed operational impact or financial gain has been documented in the cited incidents.

The actor’s observed tactics, techniques, and procedures rely heavily on spear‑phishing emails that mimic legitimate communications and are crafted after extensive surveillance of the target’s internal processes. These emails deliver malicious software designed to trick recipients and facilitate initial access to administrative or control networks. No specific malware families or additional tooling are named in the sources, but the emphasis on deceptive email content and the use of surveillance‑informed social engineering constitutes a consistent pattern across both the ARSAT and ESB incidents. The ARSAT intrusion attempt occurred in November 2022, coinciding with a high‑profile World Cup match, and prompted a pre‑emptive system‑wide shutdown despite the hackers only reaching administrative layers. The ESB campaign, reported in mid‑2017, involved similar phishing lures aimed at senior engineers, with analysts noting that successful infiltration could have allowed the actors to disrupt parts of the UK‑Northern Ireland grid, although no actual disruption was confirmed. These two campaigns illustrate the actor’s focus on high‑value infrastructure targets, reliance on credential‑harvesting via tailored phishing, and a strategic emphasis on positioning for possible disruption or intelligence collection without publicly claimed financial motives.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB