惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
D
Docker
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
博客园 - 【当耐特】
C
Check Point Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

Truesec

CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec SonicWall Vulnerabilities Exploited in the Wild - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector Critical Cisco Secure Workload Vulnerability Allows Unauthenticated Site Admin Access (CVE-2026-20223) Securing IT, OT, and IoT When the Digital Meets the Physical Russia Rolls Out Surveillance Through State-Backed “Super App” MAX
Russia Targets Businesses and Officials Behind Europe’s U...
Hjalmar Desmond · 2026-08-14 · via Truesec

Threat Insight

In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. That same year, US intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall’s CEO, whose company is central to European ammunition and armored vehicle support for Ukraine. [1]

In late 2025 and early 2026, German authorities were reportedly investigating surveillance of the CEO of German drone manufacturer Donaustahl and his family. Donaustahl forms part of the European industrial base supporting Ukraine’s drone and weapons production. [2][3]

These cases sit within a wider pattern. In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. CSIS has described this broader activity as part of Russia’s shadow war against the West. [8]

In April 2026, Russia’s Ministry of Defense publicly released addresses of European drone manufacturers supporting Ukraine. Dmitry Medvedev, Russia’s former president and current deputy chair of the Security Council, also described such sites as potential Russian targets. [4][5]

Taken together, these incidents suggest that Russia’s campaign is expanding. The focus is no longer limited to intelligence collection, sabotage or disruption of logistics. Moscow may also be prepared to pressure the people, facilities and supply chains that make European defense support to Ukraine possible. [8]

The timing matters. Ukraine’s reliance on drones has increased sharply, while European states are expanding production capacity and building joint ventures with Ukrainian firms. Russia therefore has a growing incentive to disrupt the European-Ukrainian defense-industrial base before it becomes more resilient.

Timing

This activity has developed since Russia’s full-scale invasion of Ukraine in 2022 and appears to have intensified from 2024 onward.

In 2024, Western officials warned that Russia was conducting sabotage across Europe, including arson, vandalism and assassination plots. That same year, US intelligence reportedly helped Germany disrupt a Russian plot against Rheinmetall’s CEO.

In April 2026, Russia’s Ministry of Defense publicly released addresses of European drone manufacturers supporting Ukraine. Dmitry Medvedev also described such sites as potential Russian targets.

Ukraine’s reliance on drones has increased sharply, while European states are expanding production capacity and building joint ventures with Ukrainian firms. Russia therefore has a growing incentive to disrupt the European-Ukrainian defense-industrial base before it becomes more resilient.

Geographic Scope, Actors and Targets

The threat extends beyond Germany, but the level and type of Russia-linked activity vary across Europe. Reporting points to sabotage, arson, proxy activity and espionage investigations in some countries, while others have so far mainly appeared in Russian target-signalling. [7][8][9]

Russia’s public listing of UAV-related company addresses expanded the intimidation campaign to additional countries. This matters because it separates alleged operational activity from target-signalling: some states have experienced reported Russian-linked operations, while others have so far mainly been named or exposed as potential targets. [4][5]

Russia is the primary actor, most likely acting through its intelligence services. In the cyber and logistics campaign, Western authorities have specifically attributed activity to GRU Unit 26165, while the Donaustahl reporting refers more broadly to Russian intelligence services. [1][6]

The operating model increasingly appears to combine state-led intelligence targeting with low-level recruited agents. These low-level agents are often not trained intelligence officers. Reporting describes them as disposable agents, with broader European cases showing recruitment through online channels, including Telegram. This gives Russia deniability and scale. Even failed operations can create pressure, fear and additional security costs for the target. [8][9]

The target set is not limited to major defense primes. Russia is also likely interested in small and medium-sized manufacturers, drone start-ups, component suppliers, logistics firms, IT providers and executives who publicly support Ukraine or are associated with rapid defense production. [6][7]

Tactics and Methods

Russia is using a combined campaign of surveillance, sabotage, cyber espionage, public intimidation and supply-chain targeting. [6][7][8]

In the Donaustahl case, alleged operatives reportedly filmed the CEO’s home, photographed resident information and tried to identify his whereabouts through family members. In the Rheinmetall case, US intelligence reportedly detected a mature assassination plot before German authorities increased protection around the CEO. [1][2]

These incidents show that the personal security of defense executives is now part of the attack surface.

Russia is also targeting the wider support ecosystem. GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. Observed GRU-linked activity included attempts to access shipment-related information such as train schedules, manifests, routes, cargo contents and sender/recipient details.

That intelligence can support both strategic understanding and future physical disruption. [6]

The public release of European drone manufacturer addresses is best assessed as target signalling: intimidation, information operations and possible enabling of future targeting by sympathizers or recruited proxies. When viewed alongside sabotage plots, arson cases and the reported interception of explosives allegedly bound for Bavaria, the public naming of companies should be treated as a warning indicator, not just propaganda. [4][5][7]

Implications for European Defense Industry

The Donaustahl case as well as the Rheinmetall incidents show that the personal security of defense executives is now part of the attack surface. Drone manufacturers, dual-use technology firms and newer defense-sector entrants may be especially exposed. Many are strategically important to Ukraine’s defense production, but are smaller than traditional defense primes and may have less mature physical security, counterintelligence and executive protection programs.

GRU-linked cyber activity has focused on logistics and technology companies involved in transporting aid to Ukraine. This combined with the public release of European drone manufacturer addresses is best assessed as target signalling: intimidation, information operations and possible enabling of future targeting by sympathizers or recruited low-level agents. When viewed alongside sabotage plots, arson cases and the reported interception of explosives allegedly bound for Bavaria, the public naming of companies should be treated as a warning indicator.

If you or your organization have concerns about the topic above or need support, please reach out to your Truesec contact for further assistance.

References

[1] Die Zeit / The Insider, August 2026: reporting on alleged Russian intelligence preparation of an assassination attempt against Donaustahl CEO Stefan Thumann
[2] CNN, July 2024: reporting on US and German disruption of alleged Russian plot to assassinate Rheinmetall CEO Armin Papperger
[3] BBC, July 2024: German reaction to the reported Russian assassination plot against Rheinmetall’s CEO
[4] Euractiv, April 2026: reporting on Russia publishing addresses of European drone producers and Medvedev describing them as potential targets
[5] IntelliNews, April 2026: reporting on Russian Ministry of Defence publication of Ukrainian-linked UAV enterprise locations in Europe
[6] CISA / NSA / FBI / NCSC-UK and partners, April 2026: joint advisory on Russian GRU targeting Western logistics entities and technology companies
[7] Euronews, April 2026: reporting on German intelligence warnings to the defence industry about espionage, sabotage, and attacks
[8] CSIS, March 2025: Russia’s Shadow War Against the West
[9] DR, David Blach Andersen, “Rusland hyrer teenagere til at spionere og sabotere i Europa”, 2 August 2026

Stay ahead with cyber insights

Newsletter

Stay ahead in cybersecurity! Sign up for Truesec’s newsletter to receive the latest insights, expert tips, and industry news directly to your inbox. Join our community of professionals and stay informed about emerging threats, best practices, and exclusive updates from Truesec.

Latest Insights