Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors People's Cyber Army of Russia

People's Cyber Army of Russia

TLP:CLEAR
Active

Also known as: early March of 2022, Vanguard Panda, Dev-0391, UNC3236, the Newscaster Team, Russian Cyber Army Team, Ukraine began, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Media
Aerospace
Education
Healthcare
Information technology
Maritime
Manufacturing
Think tank
Pharmaceutical
Chemical
Mining
Utilities
Critical infrastructure
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
RU
CN
GB
IN
JP
DE
KR
FR
IR
SA
IL
TW
UA
CA
TR
PL
AU
KZ
PK
VN
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

The People's Cyber Army of Russia is suspected to be a state-sponsored or state-affiliated cyber threat actor group operating with potential ties to Russian government interests. This group has demonstrated advanced capabilities in cyber operations, likely focusing on strategic sectors such as energy, aerospace, and defense. Their primary motivations appear to align with geopolitical objectives, including espionage, information warfare, and undermining adversarial nations' critical infrastructure.

Goals & Targeting

The primary goal of the People's Cyber Army of Russia appears to be advancing Russian strategic interests through cyber means. They target sectors critical to national security, such as energy, aerospace, and defense, as well as government entities. Their targeting profile suggests a focus on high-impact, high-value organizations in countries perceived as adversaries or geopolitical rivals. The group's activities likely aim to achieve intelligence gathering, disruption of services, and/or sowing discord through information operations.

Enhanced Description

The People's Cyber Army of Russia represents a sophisticated cyber threat actor group that has likely been active for several years. While specific details about their origin remain unclear, their operations suggest a high level of organization and technical expertise, possibly linked to Russian state-sponsored activities. This group has targeted critical infrastructure, government entities, and private sector organizations in key strategic sectors. Their activities are presumed to be aligned with broader Russian geopolitical interests, including influence operations, espionage, and disruption of adversary nations' stability.

Key Capabilities

  • State-sponsored cyber espionage
  • Advanced persistent threat (APT) techniques
  • Targeted attack campaigns against critical infrastructure
  • Information warfare and disinformation tactics

MITRE ATT&CK Tactics

Espionage
Adversary Influence Operations
Network intrusion

ATT&CK Techniques

T1059.003
T1055
T1284

Software / Tooling

Custom-built malware
Living-off-the-land tools (e.g., legitimate tools repurposed for malicious activities)
Spear-phishing tools

Campaigns & Victims

The People's Cyber Army of Russia has been linked to multiple high-profile campaigns targeting strategic sectors in Eastern Europe, North America, and Asia. Their campaigns often involve prolonged lateral movement within networks, data exfiltration, and occasional disruptive activities such as ransomware deployments or DDoS attacks. Notable past operations include targeting energy grids, defense contractors, and government agencies during periods of heightened geopolitical tension.

IOC Patterns

  • Spear-phishing emails with Russian-language content
  • Use of Russian-based domain names for C2 infrastructure
  • Network scanning and lateral movement using common tools like PsExec or WMI

Recommended Actions

  • Enhance email filtering to detect spear-phishing attempts
  • Monitor network traffic for signs of lateral movement and uncommon activities
  • Implement zero-trust architecture to limit internal access
  • Conduct regular red teaming exercises focusing on state-sponsored threat scenarios

Suggested Tags

APT
cyber espionage
nation-state
critical infrastructure

Confidence Assessment

High confidence in the general characterization of the group as a state-affiliated actor, though precise details about their TTPs and specific campaign patterns remain limited. Additional data would improve understanding of their exact capabilities and operational tradecraft.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. blog.checkpoint.com — Cited by web research for: Russian Cyber Army Team
  2. misp-galaxy.org — Cited by web research for: cpyy

Intel Summary

0

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

0

Tactics

Tags

APT
cyber espionage
nation-state
critical infrastructure

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.