State-Sponsored Cyber Operations in Eastern Europe: A 2026 Assessment
An analysis of recent state-sponsored cyber activities in Eastern Europe, focusing on Russian and Chinese operations targeting critical infrastructure and government entities.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Medium
- Actor Type:
- Cybercriminal
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- CVE:
- CVE-2026-21509
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of March 2026, Eastern Europe continues to be a focal point for state-sponsored cyber operations, primarily attributed to Russian and Chinese threat actors. These activities aim to compromise critical infrastructure, steal sensitive data, and exert geopolitical influence. This briefing provides an overview of recent developments, methodologies employed, and the implications for regional security.
Russian Cyber Operations
APT28's Operation Neusploit
In February 2026, the Russian-linked Advanced Persistent Threat (APT) group APT28, also known as Fancy Bear, initiated "Operation Neusploit." This campaign exploited the CVE-2026-21509 vulnerability in Microsoft Office, delivering malicious Rich Text Format (RTF) files to targets in Ukraine, Slovakia, and Romania. The malware facilitated email theft and provided backdoor access, enabling data exfiltration and remote control of compromised systems. This operation underscores APT28's rapid adoption of newly disclosed vulnerabilities and its sustained focus on Eastern European nations. (cert.europa.eu)
FROZENBARENTS Targeting Energy Sector
The Russian General Staff Main Intelligence Directorate (GRU) has been implicated in cyberattacks against Eastern Europe's energy industry. The operation, known as FROZENBARENTS, utilized compromised email servers to infiltrate networks and conduct information operations. Targets included government entities and critical infrastructure, highlighting the GRU's strategic interest in sectors vital to national security. (scworld.com)
Chinese Cyber Operations
Silver Dragon's GearDoor Malware
A Chinese state-sponsored group, identified as Silver Dragon and possibly linked to APT41, has been active since mid-2024. This group has targeted government entities in Russia, Poland, Hungary, and Italy. Silver Dragon employs sophisticated tactics, including phishing emails and exploiting exposed servers to gain initial access. Their custom malware, GearDoor, utilizes Google Drive as a command-and-control infrastructure, allowing them to disguise communications as regular files and exfiltrate data unnoticed. Additionally, they manipulate legitimate Windows services, such as Windows Update and .NET Framework utilities, to load malicious code, blending into routine system activity. Post-exploitation tools like SSHcmd and Cobalt Strike are used to deepen access and control. (techradar.com)
Implications for Regional Security
The escalation of state-sponsored cyber activities in Eastern Europe poses significant risks to national security and regional stability. The targeting of critical infrastructure, such as energy and government systems, can lead to service disruptions, economic losses, and erosion of public trust. The use of sophisticated malware and exploitation of legitimate services complicate detection and mitigation efforts, necessitating advanced cybersecurity measures and international cooperation.
Conclusion
The current threat landscape in Eastern Europe reflects a strategic use of cyber capabilities by state actors to achieve geopolitical objectives. Continuous monitoring, rapid response capabilities, and enhanced collaboration among affected nations are essential to counter these evolving threats effectively.
Sources
- CERT-EU Cyber Brief 26-03 - February 2026
- SC Media: Eastern Europe's energy industry targeted by Russian hackers
- TechRadar: Chinese hackers hide malware within Windows and Google Drive to hit government targets
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Chinese-Linked APTs Deploy AI Agents to Automate Multi-Country Cyber-Espionage Campaigns

China-Aligned APTs Pivot to AI and Robotics Espionage in South Korea and Gulf States

