News Room
16
Share
mediumCyber Espionage

Persistent APT Activity in Eastern Europe: A 2026 Overview

Recent analyses reveal sustained cyber espionage campaigns by advanced persistent threat (APT) groups in Eastern Europe, targeting government and military entities.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Persistent APT Activity in Eastern Europe: A 2026 Overview for ₿ 0.10 BTC. Contact us.

29 March 2026Last updated 29 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
APT
Geography:
Eastern Europe
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Persistent APT Activity in Eastern Europe: A 2026 Overview

As of March 2026, Eastern Europe continues to be a focal point for advanced persistent threat (APT) groups engaged in cyber espionage. These actors employ sophisticated techniques to infiltrate and maintain long-term access to sensitive governmental and military networks.

Notable APT Groups and Their Activities

  1. Ghostwriter (TA445): Originating from Belarus, Ghostwriter has been active since at least 2016. This group employs a hybrid strategy, combining disinformation campaigns with cyber espionage. Their primary targets include NATO member states, Eastern European countries, and the European Union. Ghostwriter's operations aim to undermine trust in Western institutions and influence public opinion. (brandefense.io)

  2. Winter Vivern (TAG-70): Active since 2020, Winter Vivern is linked to Belarusian intelligence services and is believed to support Russian state objectives. The group focuses on intelligence gathering, credential theft, and disrupting military communications. Their tactics include spear-phishing emails, exploitation of vulnerabilities in widely used systems like the Zimbra Collaboration Suite, and the use of lightweight PowerShell loaders for malware deployment. (brandefense.io)

  3. Angry Likho: Emerging as a significant threat in recent years, Angry Likho targets government and military organizations across Eastern Europe. The group is known for its operational agility, employing modular malware ecosystems and rapidly adapting to maintain a persistent presence. Their activities include credential theft, covert information gathering, and rebuilding quickly after being detected. (brandefense.io)

Tactics, Techniques, and Procedures (TTPs)

These APT groups exhibit several common TTPs:

  • Initial Access: Utilizing spear-phishing emails with malicious attachments or links to credential harvesting sites.

  • Exploitation: Targeting vulnerabilities in widely used systems, such as content management systems and collaboration platforms.

  • Persistence: Maintaining access through stolen credentials, long-term utilization of compromised email accounts, and the creation of false identities online.

  • Command and Control (C2): Employing compromised infrastructure and hijacked websites to funnel traffic and maintain communications.

  • Malware Deployment: Using credential harvesters, infostealers, backdoors, and publicly available tools repurposed for espionage.

Implications and Recommendations

The sustained activities of these APT groups underscore the evolving nature of cyber threats in Eastern Europe. Organizations should enhance their cybersecurity posture by implementing robust phishing defenses, regularly updating and patching systems, and conducting comprehensive network monitoring to detect and respond to unauthorized activities promptly.

Given the medium threat level associated with these groups, it is imperative for entities in Eastern Europe to remain vigilant and proactive in their cybersecurity efforts to mitigate potential risks.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo