News Room
16
Share
mediumCyber Espionage

Russian Cyber Espionage Targets Eastern European Supply Chains and Diplomacy

Russian state-sponsored cyber actors are increasingly targeting Eastern European supply chains and diplomatic entities to gather intelligence and disrupt regional stability.

31 March 2026Last updated 31 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
Nation-State
Geography:
Eastern Europe
Confidence:
Confirmed
CVE:
CVE-2026-21509
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Overview

Russian state-sponsored cyber actors have intensified their operations in Eastern Europe, focusing on long-term espionage implants, supply chain compromises, SIGINT-linked intrusions, and diplomatic targeting. These activities aim to gather sensitive information and destabilize the region.

Long-Term Espionage Implants

Russian cyber actors, notably the group known as "The Dukes," have employed sophisticated spear-phishing campaigns to establish persistent access within targeted networks. In March 2023, The Dukes targeted European diplomatic entities by sending fake Google Calendar invites that redirected recipients to malicious documents. The objective was to steal documents related to the Ukraine conflict, indicating a strategic interest in diplomatic communications. (cfr.org)

Supply Chain Compromise for Intelligence Collection

Supply chain attacks have become a prominent tactic for Russian cyber actors. In February 2026, Russian-linked APT28 conducted "Operation Neusploit," exploiting a vulnerability (CVE-2026-21509) in Microsoft Office to deliver malware via malicious RTF files. This campaign targeted government organizations in Ukraine, Slovakia, and Romania, facilitating data theft and remote access. The rapid adoption of newly disclosed vulnerabilities underscores the group's agility in exploiting supply chain weaknesses. (cert.europa.eu)

SIGINT-Linked Intrusions

Russian cyber operations have extended to intercepting satellite communications. In February 2026, EU officials reported that Russian satellites, Luch-1 and Luch-2, conducted repeated maneuvers to harvest unencrypted command links from European civilian and government satellites. This capability allows Russia to spoof orbital instructions, misalign, or crash satellites, and map users for future jamming, highlighting a sophisticated approach to SIGINT collection. (cert.europa.eu)

Diplomatic Targeting

Russian cyber actors have also targeted diplomatic entities to gather sensitive information. In March 2023, The Dukes ran a spear-phishing campaign against European diplomatic entities, posing as various embassies and sending fake Google Calendar invites that redirected recipients to malicious documents. The operation aimed to steal documents related to the Ukraine war, indicating a strategic interest in diplomatic communications. (cfr.org)

Conclusion

Russian state-sponsored cyber activities in Eastern Europe are multifaceted, encompassing long-term espionage implants, supply chain compromises, SIGINT-linked intrusions, and diplomatic targeting. These operations are designed to gather sensitive information and destabilize the region. Ongoing vigilance and enhanced cybersecurity measures are essential to mitigate these threats.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo