State-Sponsored Cyber Operations in Eastern Europe: A Critical Assessment
Recent state-sponsored cyber activities in Eastern Europe have escalated, with advanced persistent threats (APTs) targeting critical infrastructure and governmental entities, posing significant geopolitical risks.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- CVE:
- CVE-2026-21509
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Introduction
As of April 2026, the cyber threat landscape in Eastern Europe has intensified, with state-sponsored cyber operations increasingly targeting critical infrastructure and governmental institutions. These activities underscore the strategic importance of cyberspace in geopolitical conflicts and the necessity for robust cybersecurity measures.
Notable Threat Actors and Operations
-
APT28 (Fancy Bear): Attributed to Russia's GRU, APT28 has been active since at least 2007. In February 2026, the group conducted "Operation Neusploit," exploiting CVE-2026-21509 in malicious RTF files to target Ukraine, Slovakia, and Romania. This campaign delivered email-stealing and backdoor malware, enabling data theft and remote access. The rapid adoption of newly disclosed Microsoft Office vulnerabilities highlights APT28's agility and persistent focus on Central and Eastern Europe. (cert.europa.eu)
-
Sandworm: Also linked to Russia's GRU, Sandworm is known for disruptive and destructive cyber operations. Since at least 2009, the group has targeted military organizations, energy providers, telecommunications firms, election infrastructure, and public services, particularly in Ukraine and across NATO member states. Their operations often aim to cause significant disruption, as evidenced by the 2015 and 2016 attacks on Ukraine's energy grid and the 2017 NotPetya attack. (cyber-defence.io)
-
APT41 (Double Dragon): A Chinese state-sponsored group, APT41 uniquely combines state-directed espionage with financially motivated cybercrime. Operating since at least 2012, APT41 has targeted private sector companies, government institutions, and critical infrastructure across multiple continents. Their operations reflect a dual mandate: gathering strategic intelligence for the Chinese state while concurrently conducting criminal operations such as ransomware deployment, crypto-mining, and data theft for sale on criminal markets. (cyber-defence.io)
Recent Incidents and Implications
-
European Commission Data Breach: In March 2026, the European Commission confirmed a data breach involving its Europa.eu web platform, which hosts websites for several key EU institutions. The cyberattack, detected on March 24, 2026, was claimed by the ShinyHunters extortion group, which allegedly targeted the platform’s AWS-based cloud infrastructure. Although internal systems were reportedly unaffected, data theft occurred, with the attackers releasing over 90GB of sensitive materials on the dark web. This incident underscores the vulnerability of critical EU infrastructure to sophisticated cyber threats. (itpro.com)
-
EU Sanctions on Cyber Actors: In March 2026, the European Union imposed sanctions on three entities and two individuals responsible for cyber-attacks against EU member states and partners. The sanctions targeted Integrity Technology Group and Anxun Information Technology, both China-based companies, and Iranian company Emennet Pasargad. These actions reflect the EU's commitment to countering malicious cyber activities and highlight the geopolitical dimensions of cyber conflicts. (consilium.europa.eu)
Conclusion
The escalation of state-sponsored cyber operations in Eastern Europe presents a critical threat to regional stability and international security. The activities of APT28, Sandworm, APT41, and other threat actors demonstrate the evolving nature of cyber warfare, where geopolitical objectives are pursued through digital means. The recent incidents involving the European Commission and the EU's response through sanctions illustrate the complex interplay between cyber threats and international relations. It is imperative for nations and organizations to enhance their cybersecurity capabilities, foster international cooperation, and develop comprehensive strategies to mitigate the risks associated with state-sponsored cyber activities.
Highlights:
- European Commission confirms data breach as ShinyHunters group claims responsibility, Published on Monday, March 30
- [PRESS EN
Council of the EU
PRESS RELEASE
200/26
1](https://www.consilium.europa.eu/en/press/press-releases/2026/03/16/cyber-attacks-against-the-eu-and-its-member-states-council-sanctions-three-entities-and-two-individuals/pdf/?utm_source=openai), Published on Friday, March 20
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

China-Linked APT Group QTFY Escalates Targeting of Global Military and Critical Infrastructure

Chinese-Linked APTs Deploy AI Agents in Multi-Country Cyberespionage Campaign

