Russian Cyber Espionage Targets Eastern European Supply Chains and Diplomacy
Russian state-sponsored cyber actors are increasingly targeting Eastern European supply chains and diplomatic entities to gather intelligence and disrupt regional stability.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- Nation-State
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- CVE:
- CVE-2026-21509
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Overview
Russian state-sponsored cyber actors have intensified their operations in Eastern Europe, focusing on long-term espionage implants, supply chain compromises, SIGINT-linked intrusions, and diplomatic targeting. These activities aim to gather sensitive information and destabilize the region.
Long-Term Espionage Implants
Russian cyber actors, notably the group known as "The Dukes," have employed sophisticated spear-phishing campaigns to establish persistent access within targeted networks. In March 2023, The Dukes targeted European diplomatic entities by sending fake Google Calendar invites that redirected recipients to malicious documents. The objective was to steal documents related to the Ukraine conflict, indicating a strategic interest in diplomatic communications. (cfr.org)
Supply Chain Compromise for Intelligence Collection
Supply chain attacks have become a prominent tactic for Russian cyber actors. In February 2026, Russian-linked APT28 conducted "Operation Neusploit," exploiting a vulnerability (CVE-2026-21509) in Microsoft Office to deliver malware via malicious RTF files. This campaign targeted government organizations in Ukraine, Slovakia, and Romania, facilitating data theft and remote access. The rapid adoption of newly disclosed vulnerabilities underscores the group's agility in exploiting supply chain weaknesses. (cert.europa.eu)
SIGINT-Linked Intrusions
Russian cyber operations have extended to intercepting satellite communications. In February 2026, EU officials reported that Russian satellites, Luch-1 and Luch-2, conducted repeated maneuvers to harvest unencrypted command links from European civilian and government satellites. This capability allows Russia to spoof orbital instructions, misalign, or crash satellites, and map users for future jamming, highlighting a sophisticated approach to SIGINT collection. (cert.europa.eu)
Diplomatic Targeting
Russian cyber actors have also targeted diplomatic entities to gather sensitive information. In March 2023, The Dukes ran a spear-phishing campaign against European diplomatic entities, posing as various embassies and sending fake Google Calendar invites that redirected recipients to malicious documents. The operation aimed to steal documents related to the Ukraine war, indicating a strategic interest in diplomatic communications. (cfr.org)
Conclusion
Russian state-sponsored cyber activities in Eastern Europe are multifaceted, encompassing long-term espionage implants, supply chain compromises, SIGINT-linked intrusions, and diplomatic targeting. These operations are designed to gather sensitive information and destabilize the region. Ongoing vigilance and enhanced cybersecurity measures are essential to mitigate these threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

NightEagle APT Escalates Cyber Espionage Campaign Against Russian Critical Infrastructure

Chinese-Linked JDY Botnet Escalates Reconnaissance Against U.S. Military Infrastructure

