Cyber threat actors continue to evolve alongside geopolitical tensions and advances in defensive technology. State-sponsored groups, cyber espionage operators, and politically motivated hacktivists now target governments, critical infrastructure, defense organizations, technology companies, and public institutions worldwide. Their campaigns range from long-term intelligence collection to destructive attacks that disrupt essential services and influence national security.
Understanding how these threat actors operate helps security teams identify emerging risks and strengthen their defensive strategies. This guide highlights ten of the most significant Russian-linked threat actors tracked by the cybersecurity community. Each section provides an overview of the group’s objectives, operational characteristics, and current activity. You can also explore the linked threat actor profiles for detailed intelligence, including malware families, attack techniques, notable campaigns, MITRE ATT&CK mappings, and defensive recommendations.
1. Sandworm (APT44)
Overview
Sandworm is one of the most capable state-sponsored cyber threat actors operating today. Public reporting links the group to Russia’s GRU Military Unit 74455. It has conducted cyber espionage, destructive attacks, and critical infrastructure operations for more than a decade.
For a complete analysis of Sandworm’s campaigns, malware, attack techniques, and attribution, read our Sandworm Threat Actor Profile.
Why It Matters
Sandworm has demonstrated the ability to disrupt real-world operations through cyber attacks. The group has targeted government agencies, energy providers, telecommunications companies, transportation networks, and industrial control systems. Several operations have influenced how governments prepare for cyber warfare and critical infrastructure protection.
Key Characteristics
Sandworm combines long-term reconnaissance with destructive capabilities. Its operations often include custom malware, credential theft, network persistence, and coordinated disruption. Security teams frequently prioritize Sandworm because of its operational maturity and strategic objectives.
Current Status: Active. Sandworm continues to target government organizations, critical infrastructure, and military-related entities.
2. APT28 (Fancy Bear)
Overview
APT28, also known as Fancy Bear, is a long-running cyber espionage group widely associated with Russia’s GRU Military Unit 26165. The group primarily targets governments, defense organizations, political institutions, and international organizations.
Explore our APT28 (Fancy Bear) Threat Actor Profile for detailed coverage of its operations, malware, and targeting history.
Why It Matters
APT28 has remained one of the most active espionage groups for many years. The group regularly exploits newly disclosed vulnerabilities and conducts credential theft campaigns against high-value organizations. Its intelligence collection supports long-term strategic objectives.
Key Characteristics
APT28 relies on phishing campaigns, custom malware, credential harvesting, and rapid exploitation of public vulnerabilities. The group frequently adapts its infrastructure to avoid detection while maintaining access to targeted environments.
Current Status: Active. APT28 continues global cyber espionage operations against government and defense organizations.
3. APT29 (Cozy Bear)
Overview
APT29, also known as Cozy Bear, is one of the most sophisticated cyber espionage groups in operation today. Public reporting widely associates the group with Russia’s Foreign Intelligence Service (SVR). Unlike destructive threat actors, APT29 focuses on covert intelligence collection and long-term access to high-value networks.
The group has targeted governments, diplomatic organizations, healthcare providers, research institutions, and technology companies for more than a decade. Its operations emphasize stealth, persistence, and operational security rather than rapid disruption.
Learn more in our APT29 Threat Actor Profile.
Why It Matters
APT29 has built a reputation for conducting patient and carefully planned cyber espionage campaigns. The group invests significant time in reconnaissance before moving deeper into compromised environments. It often seeks sensitive diplomatic, political, scientific, and strategic information.
Researchers frequently identify APT29 as an advanced actor because it avoids unnecessary activity that could expose its presence. This disciplined approach allows campaigns to remain undetected for extended periods.
Key Characteristics
APT29 commonly uses spear-phishing, cloud account compromise, credential theft, and custom malware to establish persistence. The group also exploits trusted services and legitimate administrative tools to reduce its visibility.
Current Status: Active. APT29 continues global cyber espionage campaigns against government, diplomatic, research, and technology organizations.
4. Turla
Overview
Turla is one of the oldest known state-sponsored cyber espionage groups. Researchers have tracked its activity since the early 2000s. Public reporting generally links the group to Russia’s Federal Security Service (FSB).
Turla has developed numerous custom malware families and advanced persistence techniques throughout its operational history. Its campaigns primarily focus on intelligence collection rather than disruptive cyber attacks.
Discover more in our Turla Threat Actor Profile.
Why It Matters
Turla remains one of the most technically capable espionage groups because of its ability to maintain access to sensitive networks for long periods. The group frequently targets governments, military organizations, diplomatic missions, defense contractors, and research institutions.
Its operations demonstrate strong operational discipline and continuous technical development. Researchers continue to observe new malware variants and evolving command-and-control techniques.
Key Characteristics
Turla combines sophisticated malware with stealthy post-compromise activity. The group frequently updates its tooling and adapts to changing defensive controls. Long-term persistence remains one of its defining strengths.
Current Status: Active. Turla continues intelligence collection campaigns against government and strategic organizations worldwide.
5. Gamaredon Group
Overview
Gamaredon Group is a persistent cyber espionage actor that primarily targets Ukrainian organizations. Public reporting associates the group with Russia’s Federal Security Service (FSB). Its campaigns have expanded significantly during periods of regional conflict.
Unlike many advanced persistent threats, Gamaredon emphasizes operational volume over technical sophistication. The group launches frequent campaigns that attempt to overwhelm defensive efforts through continuous activity.
Read our detailed Gamaredon Group Threat Actor Profile.
Why It Matters
Gamaredon consistently targets government agencies, military organizations, law enforcement, and critical infrastructure. Its operations support intelligence collection and ongoing access to strategic networks.
Although its malware is generally less sophisticated than that used by other state-sponsored actors, the group’s persistence creates significant operational challenges for defenders.
Key Characteristics
Gamaredon relies heavily on phishing campaigns, credential theft, script-based malware, and frequent infrastructure changes. The group regularly modifies its tools to reduce detection and maintain campaign momentum.
Current Status: Active. Gamaredon continues large-scale espionage operations targeting Ukrainian government and military organizations.
6. Cadet Blizzard
Overview
Cadet Blizzard is a Microsoft-tracked threat actor linked to destructive cyber operations against Ukrainian organizations. Researchers have observed the group deploying custom malware and destructive payloads during periods of geopolitical conflict.
Its operations differ from traditional espionage campaigns because they prioritize disruption over long-term intelligence collection.
Explore the complete Cadet Blizzard Threat Actor Profile.
Why It Matters
Cadet Blizzard demonstrates how destructive cyber operations can support broader military objectives. The group has targeted government agencies and organizations that provide essential services during regional conflicts.
Its campaigns highlight the increasing role of cyber attacks in modern geopolitical operations.
Key Characteristics
Cadet Blizzard combines destructive malware with targeted network intrusions. The group focuses on operational disruption rather than financial gain. Its attacks often seek to interrupt business continuity and essential services.
Current Status: Active. Cadet Blizzard continues to support disruptive cyber operations against organizations linked to Ukraine.
7. Star Blizzard
Overview
Star Blizzard is a Microsoft-tracked cyber espionage group that focuses on intelligence collection through targeted social engineering and credential theft. Public reporting has linked the group to Russia’s Federal Security Service (FSB).
Its operations frequently target individuals instead of enterprise infrastructure. Common victims include government officials, researchers, journalists, and policy experts.
Learn more in our Star Blizzard Threat Actor Profile.
Why It Matters
Star Blizzard demonstrates that sophisticated cyber espionage often begins with trusted personal accounts rather than technical vulnerabilities. Successful compromises can provide valuable access to sensitive communications and confidential information.
The group’s campaigns have affected organizations involved in international relations, defense policy, and geopolitical research.
Key Characteristics
Star Blizzard frequently uses carefully crafted phishing campaigns, fake login pages, and cloud account compromise. The group adapts its social engineering techniques to match individual targets and current events.
Current Status: Active. Star Blizzard continues credential theft and intelligence collection campaigns against high-profile individuals and organizations.
8. Void Blizzard
Overview
Void Blizzard is a Microsoft-tracked cyber espionage group that primarily targets organizations with strategic or government value. Researchers have observed the group conducting intelligence collection campaigns against government agencies, defense organizations, healthcare providers, transportation companies, and critical infrastructure operators.
Although Void Blizzard is a newer public designation, its operations reflect a strong focus on long-term intelligence gathering rather than disruptive attacks.
Read the complete Void Blizzard Threat Actor Profile to explore its operations, targeting patterns, and cyber capabilities.
Why It Matters
Void Blizzard continues to expand its targeting across Europe and regions with strategic importance. The group focuses on collecting information that could support geopolitical decision-making or future cyber operations.
Its campaigns highlight the continued interest of state-sponsored actors in government networks and organizations that manage sensitive information.
Key Characteristics
Void Blizzard relies on credential theft, phishing campaigns, cloud service abuse, and legitimate administrative tools to maintain access. The group favors stealth over speed and attempts to remain undetected for extended periods.
Current Status: Active. Void Blizzard continues cyber espionage campaigns targeting government, defense, transportation, healthcare, and critical infrastructure organizations.
9. Killnet
Overview
Killnet is a pro-Russian hacktivist collective that gained international attention through large-scale distributed denial-of-service (DDoS) campaigns. Unlike traditional advanced persistent threats, Killnet publicly promotes many of its operations through online communities and social media platforms.
The group primarily targets organizations that support Ukraine or oppose Russian interests. Its campaigns focus on disrupting online services rather than maintaining long-term access to victim networks.
Learn more in our Killnet Threat Actor Profile.
Why It Matters
Killnet demonstrated how coordinated hacktivist groups can generate widespread disruption without deploying sophisticated malware. Its campaigns have affected government portals, airports, financial institutions, healthcare organizations, and transportation providers across several countries.
Although many attacks are temporary, they can interrupt public services and consume significant defensive resources.
Key Characteristics
Killnet primarily conducts DDoS campaigns supported by public recruitment and coordinated online activity. The group frequently claims responsibility for attacks and uses messaging platforms to promote its operations and encourage participation.
Current Status: Active. Killnet continues to conduct DDoS campaigns and online influence operations against organizations aligned with Ukraine and NATO member states.
10. NoName057(16)
Overview
NoName057(16) is a pro-Russian hacktivist group that focuses on distributed denial-of-service campaigns against governments and public organizations. The group emerged following Russia’s invasion of Ukraine and has remained active through coordinated online operations.
Unlike traditional espionage groups, NoName057(16) emphasizes public disruption and ideological messaging. Its operations often coincide with political events or international support for Ukraine.
Explore our detailed NoName057(16) Threat Actor Profile for a deeper analysis of its campaigns and operational methods.
Why It Matters
NoName057(16) has demonstrated that coordinated hacktivist campaigns can affect organizations across multiple countries within short timeframes. Government agencies, financial institutions, transportation providers, and public services remain common targets.
The group’s activities also illustrate how volunteer-supported cyber campaigns continue to evolve alongside geopolitical conflicts.
Key Characteristics
NoName057(16) primarily conducts coordinated DDoS attacks and publicly promotes its campaigns through messaging platforms. The group frequently encourages volunteers to participate in attacks against selected targets.
Current Status: Active. NoName057(16) continues politically motivated DDoS campaigns targeting governments and organizations supporting Ukraine.
How These Threat Actors Compare
Although these groups are often discussed together, they operate with different objectives and capabilities.
Cyber Espionage Groups
APT28, APT29, Turla, Star Blizzard, Void Blizzard, and Gamaredon Group primarily focus on intelligence collection. They seek long-term access to sensitive networks while avoiding detection.
Military Cyber Operations
Sandworm and Cadet Blizzard conduct operations that extend beyond espionage. Their campaigns have included destructive malware, infrastructure disruption, and attacks supporting broader military objectives.
Hacktivist Operations
Killnet and NoName057(16) operate differently from traditional advanced persistent threats. Their campaigns emphasize public disruption through distributed denial-of-service attacks and coordinated online messaging rather than covert intelligence gathering.
Current Threat Landscape
Russian-linked cyber threat actors continue to adapt their tactics, techniques, and procedures. They increasingly combine phishing, credential theft, cloud compromise, and legitimate administrative tools to evade detection. At the same time, hacktivist groups continue to launch disruptive campaigns that attract public attention without relying on sophisticated malware.
Organizations should monitor these threat actors because their techniques continue to evolve with geopolitical events. Strong identity protection, continuous monitoring, proactive threat hunting, and timely incident response remain essential for reducing exposure to these advanced adversaries.
Explore Detailed Threat Actor Profiles
For in-depth technical analysis, campaign timelines, malware coverage, MITRE ATT&CK mappings, indicators of compromise, and defensive recommendations, explore the dedicated profiles for each threat actor:
- Sandworm (APT44) Threat Actor Profile
- APT28 (Fancy Bear) Threat Actor Profile
- APT29 Threat Actor Profile
- Turla Threat Actor Profile
- Gamaredon Group Threat Actor Profile
- Cadet Blizzard Threat Actor Profile
- Star Blizzard Threat Actor Profile
- Void Blizzard Threat Actor Profile
- Killnet Threat Actor Profile
- NoName057(16) Threat Actor Profile
These detailed profiles provide comprehensive intelligence on each group’s history, objectives, targeting patterns, attack methods, malware ecosystem, and current operational activity. They also include practical detection guidance and mitigation recommendations to help security teams strengthen their defenses against evolving cyber threats.

