Hackfest - Level UP

Cyber in Siberia Regionalism in the GRU Information Operations Command
Language: English

This talk will explore Russia's GRU Information Operations Command through regionalization, looking at how monolithic groups such as Fancy Bear and Sandworm can be broken into subclusters. Leveraging open source information, we map out the GRU's cyber-enabled military units, attributed threat groups and capabilities to connect them to specific regions within Russia's Military Districts. The talk will draw on technical information, but humans, structure and geography have equal weight, as we explore the intersection of all these topics within the GRU.

The intent is to offer the audience the opportunity to reimagine how they consider the GRU's cyber-enabled capabilities and what that means for both attribution and their organizations. Understanding the ways organizational structure guides activity enables us as defenders to better mitigate the threat attackers pose. Attendees will leave with the knowledge that breaks through the hyperbole and approach Russian intrusions with new eyes.


Russia’s Main Directorate (GU), or more colloquially Main Intelligence Directorate (GRU)’s, Information Operations Command (VIO) represents the majority of the Russian military’s cyber-enabled capability. This talk will examine three cyber-enabled units under the VIO, - Units 26165 and 74455 - commonly referred to by their industry aliases of Fancy Bear and Sandworm respectively, as well as Military Unit 54777 (Centre for Foreign Military Information and Communication), with its attribution to the hacktivist persona (JokerDNR). While these groups only represent a portion of the offensive cyber capabilities of the Russian Federation, their relatively well-known status and media attention have created monoliths. It is often the case that due to the far reaching effects of, and the broad targeting by, these groups that little consideration has been given for how the regional nature of military operations can influence targeting preferences, objectives, and even the broader relations of these units within the VIO. It should be noted that other cyber-enabled groups such as Ember Bear exist in the GRU, however they exist outside of the VIO and are considered out of scope for this examination.

Regionalization in the Command Structure
The talk will explain how the Russian military is divided into different command regions and heir areas of responsibility

Each military district’s areas of responsibility and mission are linked to their geographic location within Russia. The VIO is present within each military district, with individual military districts having an associated Information Warfare Centre. Leaked organizational structures of the Information Warfare Centres suggests each centre maintains linguistic support for key languages in their respective areas of responsibility.

Unit 54777 - Psychological Warfare
How the utilization of open source intelligence can offer unique insight into how the different commands specialize, even down to specific military units and a specific country/linguistic focus.

Zebrocy - Initial Access as the key to the regions
How a now defunct downloader offers insight into targeting, which when combined with medal imagery and tax records, enable us to see how specific military units can have plausible links to specific elements of an intrusion.

Sandworm and the Challenge of Initial Access
Sandworm is the enigma within the GRU. They operate with far more focus and less geographic dispersement than their colleagues. However, they also are a more aggressive capability, which, during wartime, can offer an explanation. This section will explore how Sandworm operates within the context of regionality, to look at how we can break down this monolith.

Using regionality to help examine these intrusions as distinct offers the potential to map specific Tactics, Techniques and Procedures not to the monolith of Fancy Bear or Sandworm, but down to a military district, and potentially to specific military units that support these units. This can enable a deeper understanding of the GRU, allowing a more nuanced analysis of individual intrusions. Do the regional groups make use of regional specialization to gain access and conduct initial network reconnaissance before handing off access to a different unit, whether in their specific district or in Moscow? It is not clear at the moment, but it is the hope of this piece to spark discussion as to the viability of this as a means of analyzing the GRU’s cyber-enabled operations.

The speaker's profile picture
Ian Litschko

Ian is a specialist in the Russian intelligence services and Russian cybercriminal underworld. He has spoken extensively on these topics, and his work has been cited by the House of Commons and the Security Service of Ukraine (SBU).