The UK, along with international allies, exposed a unit of Russia’s military intelligence service for a campaign of malicious cyber activity targeting government and critical infrastructure organisations around the world.
The National Cyber Security Centre (NCSC) and agencies in the United States, the Netherlands, Czech Republic, Germany, Estonia, Latvia, Canada, Australia and Ukraine have published a joint advisory revealing the tactics and techniques used by Unit 29155 of the Russian GRU to carry out cyber operations globally.
The unit was part of the main directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), and conducted computer network operations against global targets for espionage, sabotage, or reputational harm since 2020.
The UK and its partners can confirm that Unit 29155 began deploying its destructive malware, WhisperGate, in 2022 against multiple Ukrainian victim organisations.
According to the joint statement, the cyber threat actors associated with this unit are separate from other known, more established Russian-affiliated groups, such as Unit 26165 and Unit 74455.
To mitigate against further malicious cyber activity, the NCSC and its associates are urging organisations to take the actions set out in its joint advisory.
This includes employing routine system updates and remediating known vulnerabilities, segmenting networks to prevent the spread of attacks, and enable phishing-resistant multifactor authentication for account services.
“The exposure of Unit 29155 as a capable cyber actor illustrates the importance that Russian military intelligence places on using cyberspace to pursue its illegal war in Ukraine and other state priorities,” Paul Chichester, NCSC director of operations, said.
Recommended reading
- Russian Midnight Blizzard Hackers Breach UK Government
- Pro-Russian Propaganda Running Unchecked on Meta in EU
- NCSC Reveals Russian Cyber Interference in UK Politics
“The UK, alongside our partners, is committed to calling out Russian malicious cyber activity and will continue to do so.
“The NCSC strongly encourages organisations to follow the mitigation advice and guidance included in the advisory to help defend their networks.”
The advisory says the Unit, which was found to be made up of junior active-duty GRU officers, also relies on those not associated with the GRU, including known cyber-criminals and enablers.





