<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz" -->

---
title: Russia Pivots Its Cyberthreats Back to the U.S. and the West
description: Google Threat Intelligence Group (GTIG) and DomainTools researchers warn that Russian state-sponsored threat actors and pro-Kremlin hacktivists are pivoting...
canonical: https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Russia Pivots Its Cyberthreats Back to the U.S. and the West | daily.dev
og:description: Google Threat Intelligence Group (GTIG) and DomainTools researchers warn that Russian state-sponsored threat actors and pro-Kremlin hacktivists are pivoting...
og:url: https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz
og:image: https://api.daily.dev/og/posts/ld5AWdhaZ.png
og:image:alt: Russia Pivots Its Cyberthreats Back to the U.S. and the West
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Russia Pivots Its Cyberthreats Back to the U.S. and the West

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 6 min read · 0 upvotes · 0 comments

## Summary

Google Threat Intelligence Group (GTIG) and DomainTools researchers warn that Russian state-sponsored threat actors and pro-Kremlin hacktivists are pivoting their cyber operations back toward the U.S., EU, and NATO after four years focused on Ukraine. Tactics include Signal Backup Recovery Key phishing campaigns targeting government officials and journalists, expanded use of generative AI for influence operations, and infrastructure attacks on water systems. The State Department has offered $10 million for information on two FSB-linked groups, UNC5792 and UNC4221. Russia's approach combines low-cost disruptive access, public fear generation, and covert influence operations at unprecedented scale.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/07/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west>

## Similar posts on daily.dev

- [A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem](https://daily.dev/posts/a-look-at-the-drivers-dynamics-and-applications-of-the-pro-russia-influence-ecosystem-qoz4luppg) · Google Cloud · 0 upvotes · 0 comments
- [Response to CISA Advisory \(AA25-343A\): Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure](https://daily.dev/posts/response-to-cisa-advisory-aa25-343a-pro-russia-hacktivists-conduct-opportunistic-attacks-against--etypghjmt) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Russia Pivots Its Cyberthreats Back to the U.S. and the West","url":"https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz"},"datePublished":"2026-07-04T03:04:45.207Z","dateModified":"2026-07-04T03:05:06.145Z","description":"Google Threat Intelligence Group (GTIG) and DomainTools researchers warn that Russian state-sponsored threat actors and pro-Kremlin hacktivists are pivoting...","image":"https://media.daily.dev/image/upload/s--OHB84bZF--/f_auto/v1722860399/public/Placeholder%2010","thumbnailUrl":"https://media.daily.dev/image/upload/s--OHB84bZF--/f_auto/v1722860399/public/Placeholder%2010","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/russia-pivots-its-cyberthreats-back-to-the-u-s-and-the-west-ld5awdhaz","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"phishing","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"Russia Pivots Its Cyberthreats Back to the U.S. and the West"}]}
```

