Persistent APT Activity in Eastern Europe: A 2026 Overview
Recent analyses reveal sustained cyber espionage campaigns by advanced persistent threat (APT) groups in Eastern Europe, targeting government and military entities.
Encrygma is selling the entire Full Cyber Weapon Research of Persistent APT Activity in Eastern Europe: A 2026 Overview for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- APT
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Persistent APT Activity in Eastern Europe: A 2026 Overview
As of March 2026, Eastern Europe continues to be a focal point for advanced persistent threat (APT) groups engaged in cyber espionage. These actors employ sophisticated techniques to infiltrate and maintain long-term access to sensitive governmental and military networks.
Notable APT Groups and Their Activities
-
Ghostwriter (TA445): Originating from Belarus, Ghostwriter has been active since at least 2016. This group employs a hybrid strategy, combining disinformation campaigns with cyber espionage. Their primary targets include NATO member states, Eastern European countries, and the European Union. Ghostwriter's operations aim to undermine trust in Western institutions and influence public opinion. (brandefense.io)
-
Winter Vivern (TAG-70): Active since 2020, Winter Vivern is linked to Belarusian intelligence services and is believed to support Russian state objectives. The group focuses on intelligence gathering, credential theft, and disrupting military communications. Their tactics include spear-phishing emails, exploitation of vulnerabilities in widely used systems like the Zimbra Collaboration Suite, and the use of lightweight PowerShell loaders for malware deployment. (brandefense.io)
-
Angry Likho: Emerging as a significant threat in recent years, Angry Likho targets government and military organizations across Eastern Europe. The group is known for its operational agility, employing modular malware ecosystems and rapidly adapting to maintain a persistent presence. Their activities include credential theft, covert information gathering, and rebuilding quickly after being detected. (brandefense.io)
Tactics, Techniques, and Procedures (TTPs)
These APT groups exhibit several common TTPs:
-
Initial Access: Utilizing spear-phishing emails with malicious attachments or links to credential harvesting sites.
-
Exploitation: Targeting vulnerabilities in widely used systems, such as content management systems and collaboration platforms.
-
Persistence: Maintaining access through stolen credentials, long-term utilization of compromised email accounts, and the creation of false identities online.
-
Command and Control (C2): Employing compromised infrastructure and hijacked websites to funnel traffic and maintain communications.
-
Malware Deployment: Using credential harvesters, infostealers, backdoors, and publicly available tools repurposed for espionage.
Implications and Recommendations
The sustained activities of these APT groups underscore the evolving nature of cyber threats in Eastern Europe. Organizations should enhance their cybersecurity posture by implementing robust phishing defenses, regularly updating and patching systems, and conducting comprehensive network monitoring to detect and respond to unauthorized activities promptly.
Given the medium threat level associated with these groups, it is imperative for entities in Eastern Europe to remain vigilant and proactive in their cybersecurity efforts to mitigate potential risks.
Highlights:
- Ghostwriter: Hybrid Influence And Espionage Operations In Eastern Europe - Brandefense, Published on Tuesday, October 28
- Winter Vivern (TAG-70 / UAC-0114 / TA473): A Persistent Eastern European Cyber-Espionage Threat Targeting NATO And EU Governments - Brandefense, Published on Thursday, February 19
- Angry Likho: Inside A Rapidly Growing Espionage Threat Targeting Eastern Europe - Brandefense, Published on Tuesday, December 16
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



