Russian government agents
Attribution profile
- Type
- Nation State
- Location
- Russia
- Known incidents
- 12 incidents
- Sources
- 3 sources
- First seen
- 2015-12-23
- Last seen
- 2024-12-19
- Updated
- 2026-08-01 04:54
- Aliases
- 7 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Russian government‑linked threat actors have been identified in open‑source reporting as the perpetrators of malware‑laden Twitter messages aimed at Pentagon employees. The sources describe them as Russian state‑affiliated hackers or Russian groups that routinely use social‑media platforms for espionage and influence operations. Their strategic objectives, as stated in the reporting, include gathering intelligence on U.S. defense personnel and shaping political discourse through covert influence campaigns.
The actors primarily target U.S. government and defense sector personnel, as illustrated by the 2017 campaign in which malicious links disguised as sports or Oscar‑related stories were sent to Pentagon workers via Twitter. In addition to espionage, they have pursued influence objectives by deploying bot networks that impersonate American teenagers with zero followers to retweet pro‑Trump content during the 2016 election cycle. These operations demonstrate a dual focus on gathering sensitive information and swaying public opinion.
Observed tactics, techniques, and procedures involve sending benign‑looking URLs that, when clicked, connect to a Russian‑controlled server delivering malware granting attackers remote control of the victim’s device and Twitter account. The actors frequently employ social‑engineering personas, such as a Russian soldier posing as a 42‑year‑old American housewife, to lend credibility to their messages. They also rely on automated bot accounts to amplify political narratives, a technique noted by the FBI as part of its investigation into election‑related influence efforts.
Attribution to the Russian state is explicitly mentioned in the source material, which cites official reports describing agents of the Russian government sending the malware‑laced messages. No specific advanced persistent threat designation is provided in the references, so the affiliation is described only as Russian government‑linked or state‑affiliated.
Representative operations highlighted in the reporting include the 2017 Twitter‑based malware assault on Pentagon workers, the 2016 election‑time botnet of zero‑follower accounts impersonating U.S. teens to spread pro‑Trump retweets, and the use of fabricated personal identities to steer political debates on the platform. These cases illustrate the actors’ reliance on social‑media vectors, persona‑based deception, and automated amplification to achieve espionage and influence goals.
Incidents
Attributed incidents are available to members.
12 incidentsSources
Sources available to members: 3 sources.