Google Threat Intelligence: the US' adversaries, especially Russia, are increasingly turning to cybercriminals and free or public malware to advance their goals
A Google Threat Intelligence Group report notes that Russia in particular has been doing this since the Ukraine war began. — Learn more.
Context & Ripple Effects
Google's threat researchers had already documented a Russia-linked Cold River escalation involving data-stealing malware in its earlier warning on Cold River's expanded tactics. Mandiant also described cases in which GRU theft was followed quickly by publication from pro-Russian hacktivist groups, illustrating an existing division of labor between state and non-state actors.
This report broadens that arc from discrete campaigns to a more general operating pattern: state objectives can be pursued through tools and operators that sit outside a clearly attributable government stack.
First-order effects
- Defenders monitoring US adversaries must treat criminally used and publicly available malware as potentially relevant to state-directed activity, rather than relying solely on bespoke-tool indicators.
- For Russia, the reported approach expands the pool of usable capabilities and intermediaries while making the boundary between espionage, disruption, and financially motivated activity less clear.
Second-order effects
- Security teams and intelligence vendors face a harder attribution and prioritization problem: the same malware families and criminal infrastructure can serve multiple motives and customers.
- The pattern reinforces demand for detection based on behavior, targeting, and operational context—not just signatures associated with named state groups.
Third-order effects
- If sustained, state use of commoditized criminal capabilities could make cyber conflict more deniable and diffuse, weakening the practical distinction between state-sponsored and criminal campaigns.
- It also strengthens the case for security strategies built around the observed state-to-hacktivist handoff and broader dual-use tooling, rather than actor labels alone.
The trend: Cyber operations are increasingly shaped by the convergence of state objectives, cybercriminal service markets, and widely accessible dual-use malware.