● OVERVIEW OF 2024
attacks: Colonel Yuri Denisov, head of
Unit 29 155, and his subordinates Nikolay Korchagin and Vitaly Shevchenko. In autumn 2024,
Harju County Court placed the suspects, who
reside in Russia, under international arrest warrants and detention orders in absentia at the
request of the Estonian Prosecutor’s Office.
This marks the first time Estonia has officially
attributed state-sponsored cyberattacks to specific individuals. The attribution of cyberattacks
is coordinated by the Ministry of Foreign Affairs
and aims to promote responsible state behaviour in cyberspace and hold actors accountable
when necessary.
ALLIES OF UKRAINE TARGETED
At the same time, Estonia and nine other countries concluded Operation Toy Soldier, which
linked Unit 29 155 to numerous cyberattacks
against Ukraine and its NATO and EU allies. As
part of this effort, the United States offered a
Cyber operations
are part of Russia’s
hybrid warfare
According to Margo Palloson, Director General
of the Estonian Internal Security Service
(KAPO), the objectives of GRU’s cyber cell,
Unit 29 155, include gathering intelligence,
causing reputational damage through the theft
and leak of sensitive information, and
systematic sabotage by destroying data and
computer systems. While the GRU unit was
officially linked to the 2020 cyberattacks,
various Russian cyber intelligence units carry
out operations against Estonia and other
nations on an ongoing basis.
The tools of Russian intelligence increasingly
blend physical and cyber capabilities, making
it likely that information obtained through
cyberattacks could be used in physical
operations. According to Russia’s military
doctrine, cyber operations are a crucial
component of hybrid warfare. Regardless of
the methods employed, Russia’s hybrid attacks
aim to impose its will on other nations, sow
instability, instil fear and create confusion.
22
$10 million reward for the capture of six Russian citizens, including Denisov and Korchagin,
who were also wanted by Estonia.
Unit 29 155 is reportedly the third GRU unit to
develop its own cyber capabilities. According to a
US indictment, the unit’s primary focus in recent
years has been on Ukraine. In early 2022, a
month before Russia’s full-scale invasion, the
unit launched the destructive WhisperGate malware attack, which targeted the Ukrainian government and law enforcement agencies, as well as
emergency services. The attack employed
destructive malware aimed not at taking control
of systems but at rendering them entirely inoperable. Since the malware was disseminated via the
services of a US-based company, the perpetrators
could also be prosecuted in the United States.
Globally, the unit’s primary objective has been
to disrupt international aid to Ukraine, according to US government data. In NATO member
states and other countries in Europe, Central
Asia and Latin America, the unit has targeted
government institutions and critical infrastructure, including banking, healthcare, transportation and energy sectors. Its activities have included defacing websites, mapping infrastructure
and stealing data, which they subsequently
either sold or leaked. Microsoft has codenamed
this GRU cyber unit Cadet Blizzard, noting that
it has also targeted IT service providers and software developers in Ukraine and other European
countries to gain access to public-sector institutions through their supply chains.
The methods employed by this GRU cyber
group are not necessarily sophisticated or
advanced. Both in Estonia and elsewhere, they
have exploited known security vulnerabilities,
such as those in email and web servers, and used
stolen user credentials to access their targets.
The unit has leveraged tools widely used in the
cybersecurity community to identify and exploit
vulnerabilities, exfiltrate data, and cover their
tracks.
LESSONS FROM THE INCIDENT
In recent years, the global cybersecurity landscape has become increasingly complex due to
rising geopolitical tensions and new technological developments, which state-sponsored
CYBER SECURITY IN ESTONIA 2025