Cyber Operations

Aggressors may conduct multi-stage attacks in the digital environment for espionage, data theft, destruction of critical infrastructure, and paralysis of state institutions. These operations span a wide range of tactics: from reconnaissance, gaining initial access (for example, through phishing, account compromise, or supply chain attacks), and establishing persistence in the system, to defense evasion, credential theft, and information exfiltration. The final stage is often a destructive effect (Impact), such as data destruction, disk wiping, or Denial of Service attacks. These techniques are covered in more detail in the specialized MITRE ATT&CK framework.

ID: T0136
Sub-techniques:  No sub-techniques
People: Ukrainians
Contributors: decolonial.ist project
Version: 1.1
Created: 21 April 2026
Last Modified: 9 August 2026

Procedures Carried Out


April 2014
C0101 Continuation of the Russo-Ukrainian War: Armed Aggression in the Donbas (2014–2015)
G0011 Russian Federation
S0017 Secret Police and Security Services

The use of a hacker group linked to the security services to compromise Ukrainian artillerymen's software: "the filename 'Попр-Д30.apk' was linked to a legitimate application which was initially developed domestically within Ukraine by an officer of the 55th Artillery Brigade named Yaroslav Sherstuk," and "in-depth reverse engineering revealed the APK contained an Android variant of X-Agent" - an implant whose exclusive operator is FANCY BEAR[1]. The same toolkit was used in cyberattacks on the Ukrainian power grid in the winters of 2015 and 2016[2][3].

February 2022
C0103 Full-Scale Invasion (from February 24, 2022)
G0011 Russian Federation
S0017 Secret Police and Security Services

Масштабные операции спецслужб РФ по кибершпионажу, перехвату данных (в том числе через взлом публичных сетей Wi-Fi) и скрытому развертыванию деструктивного ПО против украинских организаций и граждан[4][5].

References