/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Analysis of the cyber threat landscape one year after Russia invaded Ukraine shows Russia's aggressive multi-pronged plan across five phases with mixed success

One year after the Russian invasion of Ukraine, Google TAG, Mandiant, and Trust & Safety provide insights into changes in the cyber threat landscape triggered by the war.

The Keyword Shane Huntley

Context & Ripple Effects

The picture at the start of the war looked very different from this one-year mark: early coverage framed Russia's strikes on government, military, logistics and critical infrastructure as its biggest military success in the conflict to date, while analysts were still cataloguing the limits of Russian offensive cyber power before those capabilities were fully tested.

What changed over twelve months is the balance of that assessment. Google TAG, Mandiant, and Trust & Safety now score the campaign as five distinct phases with mixed results, and Microsoft had already documented spillover well beyond the front line — operations reaching 42 countries, mostly NATO members. The retrospective lands alongside coverage of the unprecedented defensive mobilization by Ukraine and its allies against wiper malware, which is the counterweight explaining why 'mixed success' is the verdict.

First-order effects

  • For Ukraine and the allied defenders Mandiant supports, the immediate effect is a validated playbook: phased campaigns are now mapped end-to-end, letting blue teams anticipate escalation stages rather than react to each wiper or intrusion as a surprise.
  • For Russia, the published phase-by-phase scoring converts operational secrecy into an intelligence loss — its targeting sequence and success rate are now public benchmarks every NATO member can plan against.

Second-order effects

  • Microsoft's finding of attacks across 42 countries forces non-belligerent NATO governments to treat themselves as secondary targets, expanding national cyberdefense budgets and threat-sharing beyond the coalition directly aiding Ukraine.
  • Defenders gain pricing and priority power: with Mandiant and Google TAG institutionalizing wartime threat intelligence, incident response and attribution become standing procurement lines for allied states rather than ad-hoc engagements.

Third-order effects

  • The norm erodes from both directions: hacking Russian targets was long considered off-limits by some operators, but the invasion triggered an unprecedented wave of attacks on Russia itself, meaning wartime cyber restraint norms may not survive their first major test.
  • If the pattern holds toward the trajectory flagged in later Google Threat Intelligence reporting, state adversaries increasingly blend official operations with cybercriminal tools and talent, blurring attribution and complicating sanctions-based deterrence.

The trend: State cyber warfare is shifting from episodic covert operations to documented, multi-year phased campaigns whose effectiveness depends as much on the defender coalition's resilience as on the attacker's arsenal.

Discussion

  • @shanehuntley Shane Huntley on x
    Our colleagues at Mandiant outline the five phases of Russian Cyber operations during the war and the use of wipers and destructive attacks. 4/7 https://twitter.com/...
  • @philvenables Phil Venables on x
    This is a spectacular report from what is now (in my view indisputably) the finest collection (breadth, depth, diversity, quality and quantity) of private sector threat intelligence operatives in existence. https://twitter.com/...
  • @hanesydd Dafydd Townley on x
    Some good stuff here. Finding 3 is probably the most interesting to consider when thinking about long-term threats. The changes in cyber crime groups in Eastern Europe will impact most current national security strategies. #cybercrime #Ukraine #strategy https://twitter.com/...
  • @shanehuntley Shane Huntley on x
    Russian government-backed attackers ramped up cyber operations beginning in 2021 during the run up to the invasion. In 2022, Russia increased targeting of users in Ukraine by 250% compared to 2020. Targeting of users in NATO countries increased over 300% in the same period. 3/7 h…
  • @hatr Hakan on x
    “Mandiant observed more destructive cyberattacks in Ukraine during the first four months of 2022 than in the previous eight years with attacks peaking around the start of the invasion” https://blog.google/...
  • @shanehuntley Shane Huntley on x
    “Fog of War: How the Ukraine conflict Transformed the Cyber Threat Landscape” TAG's biggest ever report. Along with @Mandiant and others from @Google we outline insights into changes in the cyber threat landscape triggered by the war. https://blog.google/... 1/7
  • @billyleonard Billy Leonard on x
    Really excited to see the culmination of some amazing work from some amazing people get released today. A report from @Google TAG, with contributions from friends at @Mandiant, on cyber activity related to the war in Ukraine. @t_gidwani @ShaneHuntley https://blog.google/...