Full Report
Russian intelligence services are using messaging apps and online forums to recruit Ukrainian citizens for terrorist attacks, promising quick payoffs, according to Ukraine’s law enforcement.
Analysis Summary
# Threat Actor: Russian Intelligence Services (GRU affiliation noted)
## Attribution & Identity
Attribution is made to Russian intelligence services, with specific mention of the **GRU (Russian military intelligence service)** being involved in recruitment for criminal/espionage activities. The primary actors are state-sponsored intelligence elements of the Russian Federation.
## Activity Summary
Russian intelligence services are actively engaged in large-scale efforts to destabilize Ukraine through the recruitment of Ukrainian citizens to conduct terrorist attacks and espionage operations.
* **Terrorist Recruitment:** Recruiting vulnerable Ukrainian citizens (youth, unemployed, antisocial individuals) via messaging apps and online forums to carry out terrorist attacks, often promising money.
* **Recent Attacks:** Authorities recorded nine attempted terrorist attacks since the start of the year targeting police, military recruitment centers, security services, and postal facilities, all orchestrated by Russian intelligence.
* **Espionage/Information Gathering:** Running espionage campaigns, including one involving teenagers recruited via "quest games" to photograph and video sensitive locations for use in coordinating airstrikes.
* **Surveillance:** Recruiting locals to place surveillance cameras near critical infrastructure for Russian intelligence monitoring.
## Tactics, Techniques & Procedures
- Recruitment via online platforms (messaging apps, online forums, social media).
- Offering financial rewards ("quick payoffs," "easy money") to persuade recruitment.
- Utilizing **psychological manipulation** (e.g., "quest games" for minors).
- Utilizing recruited assets for physical sabotage/terrorism (planting devices, surveying targets).
- Utilizing recruited assets for espionage (capturing geolocation data and site descriptions).
- Amplifying pro-Russian narratives and sowing discord via Telegram channels.
- Exploiting vulnerable populations for operational tasks.
## Targeting
- Sectors: Ukrainian government/security apparatus (Police, military recruitment centers, security services), Critical Infrastructure.
- Geography: Ukraine.
- Victims: Ukrainian citizens (used as unwitting or coerced operatives); Ukrainian infrastructure and security forces (targets of attacks).
## Tools & Infrastructure
- Malware families used: Not specified, but operations rely heavily on communication platforms.
- Infrastructure (C2, domains, IPs):
- **Communication Platforms:** Messaging apps (general mention), **Telegram** (specifically cited for disinformation campaigns, cyberattacks, and recruitment).
- Infrastructure use suggests reliance on anonymous communication channels to coordinate tasks and transfer data/payments.
## Implications
The primary strategic objective of these operations is to **destabilize Ukraine** and **undermine public confidence** in its security and defense forces. The use of coercion and financial incentives against vulnerable populations presents a persistent, low-cost vector for both kinetic and intelligence operations within Ukraine. The promised rewards are often hollow, as operatives are reportedly killed or imprisoned shortly after mission completion.
## Mitigations
- Increased monitoring and awareness campaigns targeting vulnerable populations regarding online recruitment scams promising money for illicit activities.
- Enhanced intelligence gathering concerning the specific messaging applications and forums used for recruitment.
- Strengthening physical security around sensitive government and military facilities in light of continued targeted attacks.
- Counter-disinformation efforts targeting pro-Russian narratives amplified on platforms like Telegram.