
criticalCyber Espionage
EU and UK Sanction Russian FSB Center 16 for Global Espionage and Grid Sabotage Campaigns
The EU and UK have issued major sanctions against Russia's FSB Center 16 and GRU following a series of aggressive cyber espionage operations and a failed 2025 power grid attack in Poland.
14 July 2026Last updated 20 August 20265 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Europe
- Confidence:
- High Confidence
- CVE:
- CVE-2018-0171
- Source:
- Mandiant
- Read Time:
- 5 min
Executive Summary On July 13, 2026, the European Council and the United Kingdom’s Foreign, Commonwealth & Development Office (FCDO) announced a joint sanctions package targeting 24 individuals and 13 entities associated with Russian state-sponsored cyber operations. This coordinated diplomatic response follows the definitive attribution of a series of escalatory espionage campaigns and a failed attempt to sabotage Poland’s electrical grid in late 2025. Encrygma Intelligence, in alignment with reporting from Mandiant and European cybersecurity authorities, identifies the primary actor as the 16th Centre of the Federal Security Service (FSB), also known as Ghost Blizzard or Berserk Bear, alongside tactical support from GRU’s APT28. ## Threat Analysis The sanctioned activity represents a significant pivot from passive intelligence gathering to active, disruptive operations. FSB Center 16 has spent the last 24 months systematically infiltrating governmental networks across France, Germany, Poland, and the Baltic states. Unlike previous cycles that focused solely on document exfiltration, the current campaign—codenamed 'Tundra Frost' by regional analysts—demonstrated a clear intent to maintain persistent access to Supervisory Control and Data Acquisition (SCADA) systems. The shift in intent highlights a broader Russian strategy to integrate cyber capabilities into a hybrid warfare framework, aiming to leverage infrastructure control during periods of geopolitical instability. ## Technical Details A cornerstone of this campaign is the deployment of the 'OceanMap' backdoor. This custom implant, written in C#, stands out for its stealthy Command and Control (C2) mechanism. OceanMap leverages the IMAP protocol to communicate with compromised mail servers, allowing malicious traffic to blend seamlessly with legitimate office communications. The malware is programmed to search for specific emails containing Base64-encoded instructions, execute the commands via cmd.exe, and then purge the inbox to minimize the forensic footprint. Additionally, the actors have been observed exploiting legacy vulnerabilities in Cisco networking hardware (notably CVE-2018-0171) and scanning for weak SNMP community strings on Ubiquiti EdgeRouters to establish initial access and pivot into internal subnets. ## Attribution Assessment Encrygma Intelligence assesses with high confidence that these operations are directed by FSB Center 16. This assessment is based on the reuse of proprietary toolsets such as OceanMap and MASEPIE, which share significant code overlaps with historical 'Ghost Blizzard' campaigns. Furthermore, the infrastructure utilized in the 2025 Polish grid incident was linked to a botnet of compromised routers previously managed by the GRU-affiliated APT28. The seamless coordination between FSB and GRU assets suggests a centralized command structure for high-priority European operations. ## Implications The official attribution and subsequent sanctions mark a hardening of the Western stance against Russian cyber aggression. By naming specific officers and private companies, the EU and UK aim to disrupt the financial and logistical support networks that sustain these APT groups. However, the discovery of disruptive intent within energy sector networks suggests that the threshold for acceptable cyber-behavior has lowered. Organizations should anticipate retaliatory 'leak-and-shame' operations or increased scanning activity against critical infrastructure sectors in the coming weeks. ## Recommendations We advise all critical infrastructure providers to perform a comprehensive audit of all edge networking devices, ensuring that default credentials are replaced and SNMP is disabled where not strictly necessary. Organizations must monitor for anomalous IMAP traffic originating from non-mail-server hosts, as this remains the primary stealth C2 channel for the OceanMap backdoor. Furthermore, implementing robust multi-factor authentication (MFA) across all remote access portals is essential to mitigating the risk of credential theft via info-stealer malware like Lumma Stealer, which has been identified as a secondary vector in these campaigns. Finally, network defenders should prioritize the isolation of IT and OT networks to prevent lateral movement into sensitive industrial control systems.
ENCRYGMA
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Share
Back to News Room