Microsoft says hackers linked to the Russian military intelligence agency formerly known as the GRU targeted conservative US think tanks that challenge Moscow
BOSTON — The Russian military intelligence unit that sought to influence the 2016 election appears to have a new target …
Context & Ripple Effects
This 2018 disclosure is the opening data point in what became a running series: Microsoft repeatedly naming Russian state hackers as they move from election-adjacent targets into the policy world itself. A year later the same actor was hitting European research groups working on election security and nuclear policy, and by 2020 Microsoft was reporting coordinated Russian, Chinese, and Iranian escalation against US election participants.
What makes the arc notable is that the targets keep moving up the value chain — from think tanks that criticize Moscow, to NGOs reached through a seized State Department aid-agency email system in the SolarWinds aftermath, to Microsoft's own source code repositories via Midnight Blizzard in 2024. The 2018 story established both the target profile (institutions shaping policy against Moscow) and the discloser (Microsoft as de facto threat-intelligence channel).
First-order effects
- Conservative US think tanks that challenge Moscow learn they are active GRU targets, forcing immediate incident-response and hardening at organizations that typically lack security staff sized for nation-state adversaries.
- Microsoft's public attribution puts pressure on Washington to treat these intrusions as part of a continuing campaign rather than isolated incidents.
Second-order effects
- Peer research institutions and NGOs — the population later hit via the SolarWinds-compromised aid-agency email system — must assume they are in the same target set and re-evaluate trust in shared email and collaboration infrastructure.
- Attribution by a private company shifts demand toward Microsoft's own security tooling and makes its threat-intelligence disclosures a competitive differentiator against other cloud providers.
Third-order effects
- If the pattern holds, espionage migrates from stealing elections to mapping the institutions that shape policy, with each disclosure widening the defined battlefield from campaigns to civil society — and eventually to the discloser itself, as Midnight Blizzard's access to Microsoft's internal systems showed.
- Private-sector attribution becomes structural: with government agencies often silent, companies like Microsoft set the public record on state hacking, concentrating intelligence-gathering power in the platforms being attacked.
The trend: Russian military-intelligence hacking is expanding from electoral interference toward sustained espionage against the think tanks, NGOs, and vendors that form the West's policy infrastructure, with Microsoft's disclosures marking each stage.