The US and allies reveal that hacker group Cadet Blizzard is part of Russia's GRU Unit 29155, which is responsible for coup attempts, assassinations, and more
There has been a lot of talk this week about Putin paying “useful idiots” to spread his propaganda. … X: @dojnatsec : Five Russian GRU Officers and One Civilian Charged for Conspiring to Hack Ukrainian Government 🔗: https://www.justice.gov/... [image] @fbi : Today, DOJ unsealed an indictment charging Russian GRU military intelligence officers—part of a group known as Unit 29155—with conducting offensive hacking operations before and after the invasion of Ukraine. Read about the indictment and Unit 29155 here: https://www.justice.gov/... Dave Luber / @nsa_csdirector : Organizations should take immediate action to secure data and mitigate harms from Russian military cyber intrusions. NSA is committed to continue providing cyber threat intelligence and mitigation recommendations. Read the latest joint guidance now and protect your networks. Steve Friend / @realstevefriend : The @FBI wasted American tax dollars indicting 6 Russians living in Russia for computer crimes against Ukraine. No one will be arrested. This is just another desperate attempt to get a headline and push a fake “Russia hacked the election” narrative. Defund the FBI. @fbi : The #FBI, @CISAgov, @NSAgov and other partners released a #CybersecurityAdvisory identifying the tactics, techniques and procedures of a group of Russian GRU military intelligence cyber actors responsible for destructive cyber operations against Ukraine: https://www.ic3.gov/... [image] Dan Black / @danwblack : WhisperGate attack (rel Cadet Blizzard, UNC2589) linked to Unit 29155: “Five of the defendants were officers in Unit 29155 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the General Staff of the Armed Forces.” https://www.justice.gov/... Eric Geller / @ericgeller : DOJ has unsealed an indictment charging 6 Russian government hackers with the “WhisperGate” wiper-malware hacking campaign against Ukrainian critical infrastructure and, later, U.S. and allied networks. https://www.justice.gov/... CISA's got an advisory: https://www.cisa.gov/... [image] @nsacyber : Russian military cyber actors continue to target U.S. and global critical infrastructure. Network defenders must regularly update mitigation measures to stay ahead of these attacks. Make sure you're up to date by reading our newest guidance: https://www.nsa.gov/... [image] John Hultquist / @johnhultquist : This announcement underscores the seriousness of some of these intrusions as well as the thin line between physical and cyber threat. Colby Badhwar / @colbybadhwar : 🇺🇲🇷🇺 FBI issuing arrest warrants for Russian Military Intelligence officers for cyber attacks against Ukraine and other western countries. [image] @mfaestonia : Today, #Estonia for the first time attributed #cyberattacks against Estonian state to the perpetrator. An international investigation has shown that 🇪🇪 among other @NATO & #EU members & #Ukraine was hit by attacks carried out by Russia's military intelligence GRU unit 29155. 1/3 [image] @ncsc : 🚨Today, the NCSC and partners have issued a joint advisory unveiling Russian military intelligence hackers for a campaign of malicious cyber activity targeting government bodies and critical infrastructure around the world https://www.ncsc.gov.uk/... Dan Black / @danwblack : 14 services in 10 countries. 🔥🔥🔥 Operation Toy Soldier is a remarkable feat of collective counterintelligence action, exposing an aggressive cyber campaign against Ukraine and NATO, now linked to one of the GRU's most brazen elements. #StrongerTogether John Schindler / @20committee : Also attacks on US spies and diplomats in many countries with their mysterious acoustic weapon, crippling and even killing Americans...but according to Biden's DNI that's just imaginary! Dan Black / @danwblack : An astute observation in Andy's piece that is often lost in the mirroring-imaging fueled rush to judgment common in analyses of Russia's cyber campaigns. “Success is measured differently in the Western world and Russia” Dean Blundell / @itsdeanblundell : It gets better. US just released a superseding indictment charging 5 Russians/Putin with everything from hacking to attempted coups to assassination attempts. Convoys too. Everything. Is. Happening. Andy Greenberg / @a_greenberg : Parents, are you monitoring what your teens are up to online? If not, they may well be carrying out cyberattacks against the Ukrainian government as part of a notorious sabotage and assassination unit of Russian military intelligence. [image] Andy Greenberg / @a_greenberg : Intelligence agencies and FBI/DOJ have revealed that unit 29155 of Russia's GRU—a unit responsible for coup attempts, assassinations, and bombings—is now engaged in brazen hacking operations with targets across the world, including in Ukraine and the US. https://www.wired.com/... LinkedIn: Brent Muir : This is an important read for anyone working in Critical Infrastructure. Russia's GRU Unit 29155 has been named as targeting global CI by US allies. … Forums: r/Intelligence : US charges Russian military officers for unleashing wiper malware on Ukraine Ars OpenForum : US charges Russian military officers for unleashing wiper malware on Ukraine
Context & Ripple Effects
The coordinated attribution links Cadet Blizzard to a GRU unit already associated in the corpus with both clandestine operations and destructive activity against Ukrainian and allied networks. It turns a previously tracked cluster into part of a named state apparatus, alongside the DOJ case against six GRU officers.
The disclosure extends a pattern of allied warnings about Russia-backed groups targeting critical infrastructure, including a Five Eyes alert on infrastructure targeting. It also fits the earlier intelligence-sharing model in which US technology companies, NATO-linked agencies, and Ukrainian defenders worked together against Russian cyber operations.
First-order effects
- US and allied defenders can fold Cadet Blizzard’s activity into Unit 29155’s published tactics and indicators, making threat hunting and incident triage more targeted for organizations exposed to Ukrainian and allied networks.
- The attribution and indictment put named GRU personnel and their alleged destructive operations under greater public and legal scrutiny, while giving CISA and partner agencies a common basis for defensive guidance.
Second-order effects
- Security vendors and critical-infrastructure operators are likely to prioritize detections for the unit’s wiper-linked tradecraft rather than treat Cadet Blizzard as an isolated cluster; the group’s reported connection to WhisperGate raises the relevance for allied networks.
- The joint disclosure reinforces the value of cross-border intelligence exchange: prior US, NATO, and Ukrainian cyber cooperation showed why operational details can matter as much as high-level attribution.
Third-order effects
- If governments continue to connect hacker personas to specific military units and officers, state-sponsored intrusion tracking may shift from group labels toward organizational and personnel-level accountability.
- The case points to a more integrated view of Russian state activity, in which destructive cyber operations are assessed alongside other clandestine tools rather than as a separate technical threat category.
The trend: Public cyber attribution is becoming more operational, pairing technical indicators with military-unit identity, legal action, and coordinated defense guidance.