A look at Russian GRU Unit 29155's hacking department, which started as a lone operator in 2012, and its involvement in cyberattack and disinformation campaigns
theins.press/en/inv/281731 @christogrozev : How the GRU's Unit 29155 hacking department obsessed over @bellingcat.com, created the biolabs conspiracy and left their targeting server unprotected....among other crazy findings in this latest investigation: theins.press/en/inv/281731 @theins.press : ‼️ Hidden Bear: The GRU hackers of Russia's most notorious kill squad — As The Insider discovered, Unit 29155, the Kremlin's most notorious black ops squad, also fielded a team of hackers that tried to destabilize Ukraine before Russia's full-scale invasion. Mastodon: Catalin Cimpanu / @campuscodi@mastodon.social : The Insider has published a profile of GRU Unit 29155, an elite GRU unit responsible for hacks, disinformation, and sabotage across Europe — https://theins.press/... Forums: r/espionage : Hidden Bear: The GRU hackers of Russia's most notorious kill squad r/craftofintelligence : Hidden Bear: The GRU hackers of Russia's most notorious kill squad
Context & Ripple Effects
The investigation adds internal history to the public attribution of Cadet Blizzard as part of GRU Unit 29155, connecting a named state-linked cluster to the unit’s broader black-ops remit.
It also fits earlier coverage of GRU cyber activity as a sustained operational capability, including documented patterns across hundreds of GRU operations, rather than an isolated campaign.
First-order effects
- The exposed targeting server and operational details can give Ukrainian, European and Bellingcat-linked defenders concrete leads for identifying infrastructure, targets and tradecraft associated with Unit 29155’s hacking team.
- The report raises the operational cost for Unit 29155 by tying its cyber activity and disinformation work more directly to a unit already associated with physical sabotage.
Second-order effects
- Government cyber agencies and threat-intelligence firms can reassess detections and attribution around Unit 29155, separating its activity more clearly from other GRU-linked clusters such as Fancy Bear’s campaigns against US targets.
- Organizations in Ukraine and Europe may treat disinformation monitoring and network defense as linked requirements when assessing Russia-linked activity, rather than as separate security functions.
Third-order effects
- If further investigations continue to expose shared infrastructure and personnel across cyber, influence and sabotage operations, attribution will increasingly focus on the state unit behind a campaign rather than only on a malware label or hacker alias.
- The case reinforces a durable defensive shift toward combining technical telemetry, infrastructure analysis and influence-operation research; its effectiveness will depend on whether exposed details translate into durable detections before operators retool.
The trend: State cyber operations are becoming more intelligible as components of integrated coercion campaigns spanning intrusion, disinformation and offline sabotage.