Russia's GRU Unit 29155 Keeps Hacking Zelensky's Office
The Ukrainian Ministry of Defense reiterated it in early July: Unit 29155 of Russia's military intelligence service, the GRU, continues to run
- The Ukrainian Ministry of Defense reiterated it in early July: Unit 29155 of Russia's military intelligence service, the GRU, continues to run
- Introduction: a military unit dedicated to hacking an elected head of state
- A confirmation that no longer surprises, yet still appalls
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: a military unit dedicated to hacking an elected head of state
A confirmation that no longer surprises, yet still appalls
The Ukrainian Ministry of Defense reiterated it in early July: Unit 29155 of Russia's military intelligence service, the GRU, continues to run hacking campaigns against Ukrainian institutions, particularly the office of President Volodymyr Zelensky and several key ministries. According to information relayed by Euromaidan Press on July 1, 2026, Ukrainian media outlets remain the number one target of Russian cyber campaigns, with one television site recently hit by a denial-of-service attack of 200,000 requests per minute sustained for roughly three hours.
Brigadier General Volodymyr Karastelov confirmed that government agencies, financial institutions, defense infrastructure and media outlets top the list of Russian targets. This is not a technical footnote reserved for cybersecurity specialists: it is documented proof that a neighboring state devotes an entire military unit to breaking into the systems of a democratically elected government.
What this commentary sets out to establish
This piece retraces what is known today about Unit 29155: its history, its methods, its recent Ukrainian targets, and the response Ukraine's security services are trying to mount against this sustained pressure. I rely exclusively on official statements and verifiable reports, without claiming to know the classified details of ongoing operations.
What stands out, reading the reports accumulated since 2022, is the continuity. This unit did not appear with the war. It was laying groundwork before the full-scale invasion even began.
Who is Unit 29155, the GRU's quiet arm
The 161st Specialist Training Center, an administrative façade
Unit 29155 is officially designated as the 161st Specialist Training Center of the GRU, Russia's military intelligence agency. According to Western investigations published since 2024, it employs roughly 400 people, including about sixty in a sub-unit dedicated to sabotage and around a dozen in a smaller but particularly active cyber wing. It is reportedly commanded by General Andrei Averyanov, a figure in Russian military intelligence already linked to several controversial foreign operations.
This unit was not created for the war in Ukraine. It existed well before, with a documented history of sabotage and assassination operations across Europe: it has notably been tied to the attempted poisoning of former spy Sergei Skripal in the United Kingdom in 2018, an attempted coup in Montenegro in 2016, and explosions at ammunition depots in the Czech Republic and Bulgaria.
A shift from physical sabotage to digital hacking
This pivot toward cyberwarfare accelerated around the 2022 invasion. According to joint investigations by several Western services, this unit was directly involved in deploying the WhisperGate malware against more than seventy Ukrainian government systems on January 13, 2022, just weeks before the full-scale invasion.
This chronological detail matters enormously: the cyberattack preceded the tanks. Digital sabotage was not a reaction to the war; it was a calculated prelude, designed to disorganize the Ukrainian state before the first shot was even fired.
The presidential office, a direct target of spear-phishing campaigns
Ministries targeted with rigged emails
Western investigations indicate that Unit 29155 ran spear-phishing campaigns — fraudulent, personalized, targeted emails — against the Ukrainian presidential office and several ministries. The goal of this type of attack is not immediate data destruction, but silent infiltration: gaining prolonged access to the internal communications of a government at war.
Brigadier General Volodymyr Karastelov publicly confirmed that government agencies rank among the priority targets of these Russian campaigns, alongside financial institutions and critical infrastructure. This official confirmation turns what might otherwise sound like an expert hypothesis into a fact established by Ukrainian authorities themselves.
Ukraine's Security Service claims thousands of thwarted attacks
Since the start of the war, Ukraine's Security Service, the SBU, says it has neutralized more than 16,000 Russian cyberattacks targeting Ukrainian systems. That figure, hard to independently verify in its technical detail, nonetheless gives a sense of the scale of this invisible war unfolding alongside the physical front.
This volume of attacks reveals a simple truth: Russia's cyberwar against Ukraine is not an occasional occurrence. It is continuous, daily pressure that mobilizes considerable human and technical resources on both the Russian and Ukrainian sides.
Ukrainian media, prime targets of the digital war
A denial-of-service attack of rare intensity
According to Euromaidan Press, a Ukrainian television site recently suffered a distributed denial-of-service attack reaching 200,000 requests per minute, sustained for roughly three hours by a network of compromised machines spread across Asia, Europe and the United States. This type of attack aims to flood a server with fraudulent traffic until it becomes inaccessible to the public.
This is not an isolated case. Back in 2025, another Ukrainian broadcasting group suffered a two-stage attack: first a phishing campaign to gain initial access, then an attempt to penetrate the technical infrastructure more deeply, foiled by Ukrainian security services before it caused irreversible damage.
Why media outlets are a strategic target
Striking Ukrainian media during a war has a clear objective: cutting off or disrupting public access to reliable information at the precise moment that information is most vital. A country that can no longer broadcast its alerts, its casualty counts or its fact-checks becomes more vulnerable to the disinformation circulating in parallel on social media.
This logic explains why Ukraine's National Council of Television and Radio Broadcasting launched, in cooperation with authorities, a cyber-resilience program covering twenty regional sites across twenty-one oblasts, training roughly 450 participants in 2026 in cybersecurity best practices for newsrooms.
A track record already documented by Western justice systems
Five GRU officers indicted in the United States
In 2024, the US Department of Justice indicted five GRU officers and a civilian for their alleged role in operations attributed to Unit 29155, offering rewards of up to $10 million for information leading to their arrest. This judicial move, rare for this type of foreign military unit, illustrates how seriously Washington now treats these activities.
The UK's National Cyber Security Centre published a joint advisory that same year with several Western allies, confirming that this Russian military unit was running cyberattack and digital sabotage campaigns far beyond the Ukrainian theater, with identified targets in Europe and North America.
Coordinated but still incomplete sanctions
New Zealand sanctioned several alleged members of this unit in 2025, while the European Union imposed sanctions on three GRU officers over hacks targeting Estonia. These measures, while real, remain scattered across multiple jurisdictions rather than coordinated under a single, systematic framework.
This fragmentation of Western responses raises a fundamental question: as long as sanctions stay piecemeal between countries, Unit 29155 will keep operating with limited personal legal risk for its members, shielded on Russian soil, out of reach of Western arrest warrants.
The broader context of Russia's hybrid war
A war that never stays confined to the battlefield
The war Russia is waging against Ukraine is not limited to the front lines in the Donbas. It includes a permanent digital dimension, an energy dimension, an information dimension, and now a maritime dimension involving the controversial use of its shadow oil fleet for surveillance operations in Europe. Unit 29155 fits squarely within this multi-domain hybrid war logic that has defined Kremlin strategy for years.
This multidimensional approach considerably complicates the task facing Ukraine's Western allies, who must simultaneously defend physical, digital and informational infrastructure against an adversary capable of striking on several fronts at once, often without ever officially claiming responsibility.
Why this concerns the West directly
Unit 29155's targets are not limited to Ukraine. Western investigations have documented similar operations in Europe and North America, meaning this unit represents a transnational threat, not merely a bilateral Russo-Ukrainian problem.
It is this transnational dimension that, according to several Western analysts, justifies a coordinated response between Ukraine and its allies, rather than an isolated defense confined to Ukrainian territory.
On the same topic
REPORT: Kaduna, Benue, Rural Nigeria Left Alone Against Its…
At least 30 people were killed when gunmen attacked a village…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
Ukraine's response, between training and technical vigilance
An unprecedented training effort for media outlets
The cyber-resilience program launched by Ukraine's National Council of Television and Radio Broadcasting reflects an institutional awakening: cybersecurity is no longer solely the concern of intelligence services; it must become a baseline skill for newsrooms themselves. Twenty regional sites, twenty-one oblasts covered, roughly 450 participants trained in 2026: these numbers show a genuine effort to democratize cyber-defense reflexes beyond specialized circles.
This decentralized approach responds to a simple reality: a poorly protected regional newsroom can become the weak link through which a broader attack infiltrates the national media ecosystem.
The structural limits of this defense
Despite these efforts, Ukrainian authorities themselves acknowledge that the threat evolves faster than some defenses. Brigadier General Karastelov did not claim the threat was under total control; instead, he confirmed its persistence and its precise targeting of the most sensitive sectors of the Ukrainian state.
This institutional honesty deserves credit: publicly acknowledging the scale of a threat, rather than downplaying it, is a necessary condition for mobilizing the resources and alliances required for effective, sustained defense.
What WhisperGate's premeditation reveals
An operation designed before the invasion even began
It is worth revisiting the timeline of WhisperGate, the malware deployed on January 13, 2022 against more than seventy Ukrainian government systems, roughly six weeks before the full-scale invasion on February 24. This timing detail is not incidental: it shows that the digital preparation for this war preceded its conventional military dimension.
Western analysts who studied this malware noted it was designed to resemble a typical ransomware attack, while actually being a pure destruction tool with no real intention of restoring data for payment. This deliberate disguise was meant to muddy attribution and slow the Ukrainian response in the critical days before the invasion.
A strategic lesson for the rest of the conflict
This digital premeditation, documented in 2022, should remain top of mind today, as the same actors continue their campaigns against the presidential office and Ukrainian media. The pattern repeats: prepare the digital ground before, during, and potentially ahead of any new military escalation.
Discover
COMMENTARY: A Supermarket in Chernihiv — the Normalization of…
On the night of July 27 to 28, 2026 , the…
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
Understanding this logic allows Western allies to anticipate, rather than simply react to, the next waves of Russian cyberattacks against Ukraine or against themselves.
The financial dimension of Russian cyberattacks
Financial institutions, a parallel target to ministries
Brigadier General Karastelov specified that Ukrainian financial institutions also rank among the priority targets of these Russian campaigns, alongside government agencies and media outlets. A successful attack against the banking system of a country at war could have consequences far broader than a simple service interruption: it would directly hit the state's ability to finance its defense effort and maintain public trust in its institutions.
This financial dimension of Russia's hybrid war remains less publicly documented than attacks on media or government, partly because financial institutions generally communicate more cautiously about the security incidents they experience, wary of eroding depositor confidence.
An underestimated systemic risk
This relative silence does not mean the risk is absent. On the contrary, several Western cybersecurity experts believe critical financial infrastructure remains among the most dangerous targets in the event of a major successful attack, precisely because its effects spread rapidly through the entire economy of a country at war.
This is a front that Ukraine and its allies must keep watching with as much vigilance as more visible targets like media or the presidential office.
The murky role of General Andrei Averyanov
A commander already named in several Western files
The name of General Andrei Averyanov comes up repeatedly in Western investigations into Unit 29155. According to several European intelligence services, he reportedly oversaw a series of foreign operations ranging from physical sabotage in Central Europe to more recent cyberattack campaigns against Ukraine. His presence at the head of this structure for several years illustrates a rare continuity of command for this type of clandestine unit.
This continuity is not trivial. It means the methods, networks and operational contacts developed during previous operations in the Czech Republic, Bulgaria or the United Kingdom may have been directly redeployed in the digital campaign against Kyiv since 2022.
A chain of command that shields its officers
Despite American indictments and European sanctions, no Western source has confirmed any direct personal sanction against General Averyanov himself to date, underscoring the practical limits of international judicial mechanisms against officers shielded by their own state.
This relative impunity constitutes, for several Western analysts, one of the most serious obstacles to effective deterrence against this type of specialized military unit.
Why this unit embodies Russia's view of Ukrainian sovereignty
A systemic contempt for democratic institutions
Devoting an entire military unit, with an identified command and a documented history of operations across Europe, to hacking the office of a democratically elected president amounts, in practice, to denying the very legitimacy of that election and that national sovereignty. It is no accident that Volodymyr Zelensky's office figures explicitly among the confirmed targets of these campaigns.
This logic fits within a broader Kremlin narrative that has, for years, publicly disputed the legitimacy of the Ukrainian state as a political entity distinct from Russia. Digital hacking then becomes an extension of that ideological challenge by technical means.
A troubling precedent for other democracies
What is unfolding against the Ukrainian presidential office today could foreshadow what other Western democracies might face tomorrow, should hostile actors decide to apply similar methods against their own elected institutions.
It is precisely for this reason that cooperation between Ukrainian services and their Western counterparts, already documented through joint cybersecurity advisories published since 2024, must keep deepening rather than easing off.
The limits of what can be affirmed today
What the sources confirm and what they do not
It is important to distinguish what qualifies as publicly confirmed fact — the existence of Unit 29155, its role in WhisperGate, the 2024 American indictments, Brigadier General Karastelov's statements on priority targets — from what remains, at this stage, publicly undetailed: the exact content of the most recent spear-phishing emails, or the precise extent of any actual penetration of targeted systems in 2026.
This caution does not weaken the overall finding. It actually strengthens it: what is known with certainty already suffices to establish the reality of a structured, persistent Russian campaign against Ukrainian institutions.
Vigilance that must stay documented, never speculative
Faced with this kind of file, the temptation to extrapolate beyond confirmed facts runs high. This piece chose to stick to official statements and verifiable investigations, rather than adding unverifiable details that would weaken the credibility of the overall finding.
It is this rigor that ultimately allows for clearly naming Russian responsibility without ever crossing the line into unfounded speculation.
What this means for the months ahead
A threat that will not fade on its own
Nothing in Unit 29155's history suggests it will scale back its activities against Ukraine as long as the war continues. On the contrary, the persistence of its methods since 2022, despite Western indictments and sanctions, shows these legal and diplomatic measures have not yet reached a level sufficient to meaningfully deter this type of operation.
The coming months should see this type of campaign continue, if not intensify, particularly around politically sensitive moments for Ukraine, where disrupting government or media communications would hand the Kremlin an additional tactical advantage.
What the West should take away from this
The most important lesson from this file is not only Ukrainian. It concerns all Western democracies facing state actors willing to deploy entire military units to undermine elected democratic institutions, using means that largely escape classic legal categories of warfare.
Strengthening international coordination on this file, beyond the current scattered sanctions, appears to be the only response equal to the persistence this unit has demonstrated over several years now.
What Washington and Brussels could still do
Concrete options still on the table
Several Western analysts argue for harmonizing sanctions specifically targeting identified members of Unit 29155, rather than the current patchwork of separately applied American, European and New Zealand measures. A shared list, coordinated among Washington, Brussels and their G7 partners, would strengthen both the symbolic and practical reach of these sanctions.
Strengthening technical intelligence sharing between Ukrainian and Western services, already underway since 2024 through joint cybersecurity advisories, could also speed up early detection of new campaigns before they reach their final targets.
The political cost of inaction
Doing nothing further also carries a cost: every month without a coordinated response reinforces the sense, within the Kremlin, that these operations can continue without meaningful consequence for those who order them. That is a signal the West can no longer afford to send, as the war enters its fifth year.
This holds true for cyberwarfare just as much as for other dimensions of the conflict: historically, a slow Western response has always benefited Moscow.
Conclusion: naming the threat is not enough, it must be contained
A file that goes beyond Ukraine alone
Unit 29155 of the GRU is not a technical curiosity reserved for cybersecurity specialists. It is the instrument of a deliberate strategy aimed at weakening a sovereign state through digital means, before, during, and probably after any shift in the conflict on the ground. Its confirmed targeting of the Ukrainian presidential office, ministries, financial institutions and media outlets draws a coherent picture: that of a hybrid war that knows no truce, even when the guns fall temporarily silent.
American indictments, European and New Zealand sanctions, and Ukrainian efforts to train for cyber-resilience constitute real responses, but ones still insufficiently coordinated against the persistence of this threat.
What to watch in the coming months
The true measure of Western seriousness on this file will be seen in the ability, or inability, of Ukraine's allies to harmonize their sanctions and cyber-defense mechanisms against a unit that, for its part, continues operating with remarkable strategic continuity after more than four years of open war.
It is this Russian continuity, more than any single one-off statement, that should guide Western vigilance in the months ahead.
By Maxime Marquette, columnist
Columnist's transparency note
My acknowledged biases
I sign this commentary as an engaged observer of the Western camp, not as a neutral journalist. I fully support the sovereignty of Ukraine, and I regard Volodymyr Zelensky as a leader who has shown exceptional courage in the face of Russian aggression. I consider Vladimir Putin's Russia, alongside China, Iran and North Korea, a structural threat to the rules-based international order.
What I do not claim to know
I do not know the exact content of the most recent spear-phishing emails attributed to Unit 29155, nor the precise extent of any actual penetration of Ukrainian systems in 2026. This commentary relies solely on official statements, public Western judicial investigations and verifiable cybersecurity reports, without invented testimony or speculation presented as established fact.
Sources
Primary sources
Ministry of Defense of Ukraine — security and cyber-defense context, July 2026
Euromaidan Press — Ukrainian media, the number one target of Russian cyberattacks, July 1, 2026
Army Inform — Ukrainian defense and cybersecurity news, July 2026
Secondary sources
Foreign Policy — analysis of Russia's hybrid war
The Guardian International — coverage of Russian cyberattacks against Ukraine
Axios — geopolitical context of the Russo-Ukrainian cyberwar
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). Russia's GRU Unit 29155 Keeps Hacking Zelensky's Office. MadMax. https://mad-max.co/en/article/l-unite-29155-du-gru-quand-moscou-pirate-le-bureau-de-zelensky
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.