News Room
16
Share
mediumState Cyber Warfare

State-Sponsored Cyber Operations in Eastern Europe: A 2026 Assessment

An analysis of recent state-sponsored cyber activities in Eastern Europe, focusing on Russian and Chinese operations targeting critical infrastructure and government entities.

25 March 2026Last updated 25 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Medium
Actor Type:
Cybercriminal
Geography:
Eastern Europe
Confidence:
Confirmed
CVE:
CVE-2026-21509
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Introduction

As of March 2026, Eastern Europe continues to be a focal point for state-sponsored cyber operations, primarily attributed to Russian and Chinese threat actors. These activities aim to compromise critical infrastructure, steal sensitive data, and exert geopolitical influence. This briefing provides an overview of recent developments, methodologies employed, and the implications for regional security.

Russian Cyber Operations

APT28's Operation Neusploit

In February 2026, the Russian-linked Advanced Persistent Threat (APT) group APT28, also known as Fancy Bear, initiated "Operation Neusploit." This campaign exploited the CVE-2026-21509 vulnerability in Microsoft Office, delivering malicious Rich Text Format (RTF) files to targets in Ukraine, Slovakia, and Romania. The malware facilitated email theft and provided backdoor access, enabling data exfiltration and remote control of compromised systems. This operation underscores APT28's rapid adoption of newly disclosed vulnerabilities and its sustained focus on Eastern European nations. (cert.europa.eu)

FROZENBARENTS Targeting Energy Sector

The Russian General Staff Main Intelligence Directorate (GRU) has been implicated in cyberattacks against Eastern Europe's energy industry. The operation, known as FROZENBARENTS, utilized compromised email servers to infiltrate networks and conduct information operations. Targets included government entities and critical infrastructure, highlighting the GRU's strategic interest in sectors vital to national security. (scworld.com)

Chinese Cyber Operations

Silver Dragon's GearDoor Malware

A Chinese state-sponsored group, identified as Silver Dragon and possibly linked to APT41, has been active since mid-2024. This group has targeted government entities in Russia, Poland, Hungary, and Italy. Silver Dragon employs sophisticated tactics, including phishing emails and exploiting exposed servers to gain initial access. Their custom malware, GearDoor, utilizes Google Drive as a command-and-control infrastructure, allowing them to disguise communications as regular files and exfiltrate data unnoticed. Additionally, they manipulate legitimate Windows services, such as Windows Update and .NET Framework utilities, to load malicious code, blending into routine system activity. Post-exploitation tools like SSHcmd and Cobalt Strike are used to deepen access and control. (techradar.com)

Implications for Regional Security

The escalation of state-sponsored cyber activities in Eastern Europe poses significant risks to national security and regional stability. The targeting of critical infrastructure, such as energy and government systems, can lead to service disruptions, economic losses, and erosion of public trust. The use of sophisticated malware and exploitation of legitimate services complicate detection and mitigation efforts, necessitating advanced cybersecurity measures and international cooperation.

Conclusion

The current threat landscape in Eastern Europe reflects a strategic use of cyber capabilities by state actors to achieve geopolitical objectives. Continuous monitoring, rapid response capabilities, and enhanced collaboration among affected nations are essential to counter these evolving threats effectively.

Sources

  • CERT-EU Cyber Brief 26-03 - February 2026
  • SC Media: Eastern Europe's energy industry targeted by Russian hackers
  • TechRadar: Chinese hackers hide malware within Windows and Google Drive to hit government targets
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo