Category
World

Russian State-Backed Hackers Target US Defense and Nuclear Organizations

3 min read
Google logo Prefer U24 Media on Google
Authors
Photo of Roman Kohanets
News Writer
Analysts work in the Security Operations Center at the Dell SecureWorks office in Myrtle Beach, South Carolina, US, on January, 18, 2013. (Source: Getty Images)
Analysts work in the Security Operations Center at the Dell SecureWorks office in Myrtle Beach, South Carolina, US, on January, 18, 2013. (Source: Getty Images)

Russian hackers spent the past year targeting the emails of US nuclear scientists, defense contractors, and government employees, according to researchers and Western intelligence agencies, on July 24.

The warning came in a joint advisory from security and intelligence agencies in the US and more than a dozen allied countries, CNN reported on the same day.

The US cybersecurity firm Proofpoint documented part of the same activity in its own investigation published on July 23.

We bring you stories from the ground. Your support keeps our team in the field.

DONATE NOW

Researchers said the targets suggested Russian interest in nuclear fusion research and intelligence that could support the Kremlin’s war against Ukraine.

The operatives refined their methods on Ukrainian targets before deploying them against NATO members, the advisory noted.

“It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO,” UK Security Minister Dan Jarvis stated.

The federal advisory described the espionage campaign as ongoing and built around a rare software exploit. A target only has to open an email on a vulnerable system; no link needs to be clicked.

The exploit can extract up to three months of email correspondence, along with an organization’s entire email directory.

A phishing email masquerading as a cooperation proposal from the fictitious “Cooperation Belgian Foundation,” used by Russian threat actors in October 2025 to target European organizations. (Source: Proofpoint)
A phishing email masquerading as a cooperation proposal from the fictitious “Cooperation Belgian Foundation” was used by Russian threat actors in October 2025 to target European organizations. (Source: Proofpoint)

The US and its allies said the hackers targeted federal and local government bodies, law enforcement agencies, defense organizations, education, and energy sectors without identifying individual victims.

Proofpoint’s investigation found the hackers targeted email servers used by what the company described as “nuclear installations and the defense industrial base” in the US.

Sherrod DeGrippo, vice president of threat intelligence at Palo Alto Networks’ Unit 42, which has tracked the same activity, said the campaign was also likely intended to gather intelligence on Western military logistics, procurement, and policy.

The advisory also described a broader pattern in which Russian cyber groups first target Ukrainian organizations before deploying the same techniques against Western countries. It warned that the group was likely to continue targeting email systems operated by Western organizations.

Brett Leatherman, assistant director of the FBI’s cyber division, told CNN this month that Russian cyber targeting of the US had quieted after the start of the full-scale war in Ukraine in 2022. Over roughly the past year, he said, the bureau has recorded an uptick.

Law enforcement has also pursued the group. Thai authorities arrested an alleged member in November, a Russian man in his 30s who was extradited to the US and made his initial court appearance in Boston last month, Reuters reported.

The Department of Energy, which oversees multiple laboratories focused on nuclear energy, did not respond to a request for comment on Proofpoint’s findings. The FBI and the National Security Agency said officials were not immediately available for interviews about the advisory. The Russian Embassy in Washington also did not respond.

Earlier, in July, a large-scale espionage operation was uncovered that had compromised internet-connected security cameras along military transport routes in NATO member states, including the Netherlands, and in Ukraine.

Many of the devices still ran on default passwords and outdated firmware, allowing Russian operators to monitor the movement of weapons shipments bound for Kyiv and identify their contents.

See all

Never miss our investigations

Make UNITED24 Media a preferred source on Google and get our exclusive reporting from Ukraine at the top of your feed.