Aggressors may conduct multi-stage attacks in the digital environment for espionage, data theft, destruction of critical infrastructure, and paralysis of state institutions. These operations span a wide range of tactics: from reconnaissance, gaining initial access (for example, through phishing, account compromise, or supply chain attacks), and establishing persistence in the system, to defense evasion, credential theft, and information exfiltration. The final stage is often a destructive effect (Impact), such as data destruction, disk wiping, or Denial of Service attacks. These techniques are covered in more detail in the specialized MITRE ATT&CK framework.
The use of a hacker group linked to the security services to compromise Ukrainian artillerymen's software: "the filename 'Попр-Д30.apk' was linked to a legitimate application which was initially developed domestically within Ukraine by an officer of the 55th Artillery Brigade named Yaroslav Sherstuk," and "in-depth reverse engineering revealed the APK contained an Android variant of X-Agent" - an implant whose exclusive operator is FANCY BEAR[1]. The same toolkit was used in cyberattacks on the Ukrainian power grid in the winters of 2015 and 2016[2][3].