Full Report
A previously unknown hacking group has spent nearly two years quietly targeting Russian maritime universities, energy facilities, diplomatic missions and government agencies, according to new research. The campaign, which researchers at Russian cybersecurity firm Kaspersky said dates back to at least 2024, remained undetected for years and featured long periods of inactivity that helped conceal the group’s…
Analysis Summary
# Threat Actor: [Unknown / Unnamed]
## Attribution & Identity
* **Identification:** A previously unknown hacking group first identified by researchers at Kaspersky.
* **Aliases:** None currently assigned (identified as an "Unknown group").
* **Known Associations:** No confirmed links to existing APT groups were mentioned in the source article, though its focus is on high-value Russian targets.
## Activity Summary
* **Duration:** Operational since at least 2024 (active for nearly two years as of mid-2026).
* **Operational Tempo:** Characterized by "long periods of inactivity" (3–4 months) followed by "bursts of activity" featuring up to 10 attacks in a single month.
* **Current Status:** Actively targeting Russian infrastructure through mid-2026.
## Tactics, Techniques & Procedures
* **Operational Security (OPSEC):** High level of discipline; uses prolonged dormancy to evade detection by security monitoring and baseline behavioral analysis.
* **Specific TTPs:** While specific MITRE ATT&CK IDs were not explicitly detailed in the summary, the actor demonstrates:
* **Stealthy Persistence:** Maintaining access for years without detection.
* **Strategic Dormancy:** Deliberate pauses in C2 activity to bypass automated threat hunting.
## Targeting
* **Sectors:**
* Maritime (specifically universities and training centers)
* Energy (critical infrastructure and facilities)
* Government (federal agencies)
* Diplomatic (missions and embassies)
* **Geography:** Primarily Russia.
* **Victims:** Russian maritime universities, energy facilities, and diplomatic missions.
## Tools & Infrastructure
* **Malware families:** Specific malware payloads were not named in the provided brief (referred to the broader Kaspersky research).
* **Infrastructure:** Infrastructure is noted for being used sparingly during dormant periods to avoid IP/domain blacklisting.
* *C2/Domains:* hxxps[://]securelist[.]ru/unknown-group-targets-maritime-universities/115765/ (Research Reference)
## Implications
* **Strategic Intelligence:** The focus on maritime universities and energy suggests a long-term interest in maritime logistics, naval preparation, and national energy security.
* **Threat Assessment:** This actor represents a highly sophisticated threat capable of persistent, "low-and-slow" operations. Their ability to remain undetected for years inside sensitive Russian networks suggests a high level of resource backing, typical of state-sponsored entities.
## Mitigations
* **Behavioral Monitoring:** Implement long-term trend analysis that looks beyond 90-day windows to identify bursts of activity from dormant accounts or hosts.
* **Hunting for Persistence:** Conduct regular hunts for unauthorized persistence mechanisms in maritime and energy ICS/IT environments.
* **Network Segmentation:** Strictly segment university and research networks from government-affiliated diplomatic or energy communications to prevent lateral movement.