Ian Litschko 's Avatar

Ian Litschko

@ilitschko

Russian cyber espionage and cybercrime| Carleton University and MGIMO | GTA Khachipuri

1,113
Followers
406
Following
85
Posts
07.08.2023
Joined
Posts Following

Latest posts by Ian Litschko @ilitschko

Post image

Tonight's beer.

08.03.2026 00:32 👍 0 🔁 0 💬 0 📌 0
Post image

1/ Anti Lukashenko-regime hackers Belarusian Cyber Partisans melden:

‘CYBERATTACK ON Khimvolokno 💥

We're striking the computer network of Belarusian Khimvolokno, Russia's largest supplier of nylon threads used to make helmet linings and body armor for the Russian army’.

26.02.2026 19:26 👍 1 🔁 1 💬 1 📌 0
СК обвинил москвича в вымогательстве у «хакеров-патриотов» под видом ФСБ Руслан Сатучин представлялся сотрудником ФСБ и требовал деньги у «патриотической» хакерской группировки Conti за непривлечение к ответственности, считает следствие

Weird cyber story from Russia: a Moscow resident Ruslan Satuchin faces criminal charges for allegedly contacting Conti under the pretense of the FSB & extorting money for protection. Now he's investigated for fraud

No word of legal action against Conti

www.rbc.ru/society/25/0...

25.02.2026 05:33 👍 6 🔁 7 💬 0 📌 0

Wanted: foreign mercenaries, oops, military recruits seeking a path to citizenship...

19.02.2026 09:18 👍 8 🔁 5 💬 0 📌 0

The Wagner network recruits economically vulnerable Europeans for acts of violence and sabotage on NATO soil. GRU and FSB run the operations; Wagner supplies the channels and recruiters who "speak the language" of the marginalised. Many attacks have been thwarted. www.ft.com/content/dbd1...

15.02.2026 18:30 👍 22 🔁 9 💬 1 📌 0

Today, INPACT reveals the takeover of the Wagner Group's influence arm – Africa Politology – by the SVR, Russia's foreign intelligence service.

14.02.2026 06:49 👍 28 🔁 33 💬 1 📌 0
Preview
“Pancake,” “Lenin,” and an FSB hacker: Meet the fresh faces at Putin’s new directorate “for strategic partnership and cooperation” In August 2025, Putin abolished the Directorate for Interregional and Cultural Relations with Foreign Countries, which had been responsible for promoting “soft power” (and for spying, of course) and r...

“Pancake,” “Lenin,” and an FSB hacker: Meet the fresh faces at Putin’s new directorate “for strategic partnership and cooperation”

Despite a nominal rebranding, the Kremlin’s efforts to peddle Russian soft power abroad look set to remain unchanged.

13.02.2026 19:59 👍 7 🔁 2 💬 0 📌 1
Preview
(S+) Hacktivist infiltriert Desinformationskampagne: Im Inneren der russischen Propagandamaschine Informationskrieger des Kreml machen im Netz Stimmung gegen Kanzler Merz, die »Zukunft« gelte der AfD. Ein Hacktivist liefert tiefe Einblicke in Moskaus Maschinenraum.

In case you're interested in #Doppelgänger and are following disinfo, here's a piece about a hacktivist who managed to siphon out hundreds of gigabytes of internal data (zipped!)

Article at Der Spiegel, Gift Link
www.spiegel.de/politik/hack...

12.02.2026 17:39 👍 19 🔁 12 💬 2 📌 0
Preview
Давно не секрет фирмы В России растет число кибератак с целью шпионажа

Kommersant cites BI.ZONE CTI that 37% of cyber attacks on Russian organizations in 2025 were conducted for espionage, up from 21% in 2024. 45% of the threat groups attacking Russia and CIS are espionage groups.
Kommersant.ru/doc/8420782

11.02.2026 16:37 👍 0 🔁 1 💬 0 📌 0

The main difference I can see so far is my hypothesis that initial access occurs at the regional level, leveraging the regional focus of individual military districts.

Just mostly glad to see significant alignment in my research.

09.02.2026 17:46 👍 0 🔁 0 💬 0 📌 0

Someone putting pen to paper GRU regionality, something I've been researching for the past few years. Based on imagery they include, we use similar methodologies to break down the VIO by regions and links to monoliths, and reach similar conclusions.

09.02.2026 17:46 👍 1 🔁 1 💬 1 📌 0
Preview
Cyber spies use fake New Year concert invites to target Russian military The campaign surfaced earlier in October after researchers at the New York-based cybersecurity firm Intezer identified a malicious XLL file uploaded to VirusTotal, first from Ukraine and later from Ru...

Researchers said they observed a hacking group attempting to lure senior Russian military officers to download malware using a variety of phishing emails therecord.media/cyber-spies-...

22.12.2025 17:54 👍 3 🔁 2 💬 0 📌 0
Post image

First day of vacation beer at the Canadian Warplane Heritage Museum.

12.12.2025 17:21 👍 3 🔁 0 💬 0 📌 0
Preview
Bundesregierung macht Russland für Cyberangriff verantwortlich Die Bundesregierung wirft Russland einen großen Cyberangriff auf die Flugsicherung und eine Desinformationskampagne im Bundestagswahlkampf vor. Der russische Botschafter wurde ins Auswärtige Amt einbe...

Germany seems more willing to call out Russia - today the government is accusing Russia of a large scale cyber attack on air traffic security and for disinformation campaign during the federal elections earlier this year:

12.12.2025 11:44 👍 133 🔁 41 💬 4 📌 2
Preview
История большого взлома. Как хакеры парализовали «Аэрофлот» С начала войны число атак украинских и белорусских хакеров на крупные российские компании выросло кратно, но не всегда о них

Blockbuster reporting by Maria Kolomychenko on the Aeroflot hack with new details on messy infosec, the impact of & recovery from what was the biggest cyber attack on Russia during the war

thebell.io/istoriya-bol...

09.12.2025 16:14 👍 5 🔁 3 💬 0 📌 1
Post image

Another day another Belarusian picked up by the Poles for spying and “sabotage”

09.12.2025 12:46 👍 38 🔁 5 💬 1 📌 0
Preview
Profile: GRU cyber and hybrid threat operations

The UK has updated their GRU cyber profiles today. I love the breakdown of Fancy Bear into at least 3 distinct teams. It helps the research I've been doing into subgroups and regionalization within the GRU, trying to break down monoliths into a military district based understanding of GRU cyber ops.

04.12.2025 14:32 👍 3 🔁 2 💬 0 📌 0

It strikes me that people make fun of American politicians or influencers who post AI nonsense. But when Russia, China or Iran does the same thing, people act like they're sophisticated threat actors capable of shaping global opinion at will.

02.12.2025 17:46 👍 2 🔁 1 💬 0 📌 0
Post image

Always fun to see the reason one of your instructors got the job at MGIMO.

18.11.2025 17:56 👍 0 🔁 0 💬 0 📌 0

Off bright and early to DC for Cyberwarcon.

18.11.2025 11:11 👍 1 🔁 0 💬 0 📌 0
Russian alleged cyber-hacker faces extradition to US after arrest in Thailand | CNN

Oh ok so it wasn’t a GRU operator (necessarily) — it was a guy working as part of the recently identified threat group that pissed off Dutch intelligence

15.11.2025 22:41 👍 12 🔁 2 💬 1 📌 0
Preview
Once Upon a Russia: Voices From a Vanished Era Amazon.com: Once Upon a Russia: Voices From a Vanished Era: 9781737766346: Fisher, Steven A.: Books

The indefatigable Steven Fisher, formerly of Citibank Russia and Citibank Ukraine, has assembled this collection of remembrances from former expats in Russia. There is so much here, so many memories of a Russia vanished. I reminisced about riding the rails ( scottgehlbach.net/posts/4055-r...).

15.11.2025 03:23 👍 3 🔁 1 💬 0 📌 1
Preview
The elite Russian unit hunting Ukraine’s drone warriors Moscow’s new Rubikon team upends Kyiv’s control of the electronic battlefield

FT report: Russia’s Rubikon unit is upending Ukraine’s drone advantage — locating & killing operators deep behind the lines, training other Russian teams, & seizing control of Ukraine's decisive "electromagnetic spectrum." Ukrainian pilots now face relentless pressure, must adapt tactics to survive.

13.11.2025 22:49 👍 23 🔁 10 💬 0 📌 0
Preview
В Таиланде арестовали «всемирно известного» российского хакера по запросу США. Предположительно, это сотрудник ГРУ Алексей Лукашев Тайская киберполиция сообщила об аресте на Пхукете 35-летнего гражданина России, которого американские власти разыскивают по обвинению в хакерских атаках на государственные структуры Европы и США

It is apparently very hard to use Yandex to search "what countries extradite to the US?"

theins.ru/news/286794

13.11.2025 18:51 👍 1 🔁 0 💬 0 📌 0
Post image

Tonight's bottle of Georgian.

04.11.2025 23:38 👍 0 🔁 0 💬 0 📌 0

Don’t let anyone tell you that the Russians never arrest cybercriminals. Criminals who cause harm to Russians are regularly arrested, and as this instance shows, often dealt with harshly. See my timeline for a modest sampling of other arrests of hackers, fraudsters, and other Russian cybercriminals.

09.10.2025 11:48 👍 0 🔁 1 💬 0 📌 0

What we report publicly and attribute vs what they report publicly and attribute are wildly different beasts. Wish Bi Zone gave some geographic attribution but will take what I can get right now.

08.10.2025 22:13 👍 0 🔁 0 💬 1 📌 0

I think super important to track what they're saying about what they fear, what they think war looks like, & what they think adversaries will do, as well as what they themselves hope to do & what they actually do. Also crucial to track the disconnects between these & whether & when they narrow. 7/7

08.10.2025 15:30 👍 6 🔁 2 💬 1 📌 0
Preview
Gamaredon X Turla collab ESET researchers reveal how the notorious APT group Turla collaborates with fellow FSB-associated group known as Gamaredon to compromise high‑profile targets in Ukraine.

Most interesting to me is that the cooperation between Gamaredon and Turlais distinct from the Gamaredon cooperation with Invisimole. They are really solidifying themselves as an initial access team within the FSB.

www.welivesecurity.com/en/eset-rese...

19.09.2025 17:28 👍 3 🔁 0 💬 0 📌 0