SecureWorld News

The Kremlin's Long War Comes Home to Your Endpoints

Written by Cam Sivesind | Tue | Sep 29, 2026 | 2:18 PM Z

Russia is escalating a quiet, deniable war across Europe—one fought with drones, arson, disinformation, and increasingly, malware built and sold out of the Moscow region. Two pieces of research published within a day of each other, one strategic and one deeply technical, show the same threat from opposite ends of the telescope. Read together, they tell security teams something uncomfortable: the geopolitics on the front page and the malware on the endpoint are branches of the same tree.

In a September 24th assessment, Recorded Future's Insikt Group lays out a stark forecast. Since Russia's full-scale invasion of Ukraine in February 2022, Russia has escalated its use of hybrid, asymmetric warfare across Europe, far beyond the former Soviet Union, where Russia historically focused its aggression. The umbrella term is New Generation Warfare (NGW)—a doctrine Russian military officials articulated more than a decade ago.

The concept isn't new so much as newly aggressive. Asymmetric responses to perceived provocations by Russia's adversaries date back to at least the Soviet Union, when such tactics were called "active measures." What separates NGW from conventional war is that it does not involve troops moving across a country's border or a state's military dropping bombs on an adversary's capital city. Instead, it is a complex kit of psychological, cyber, and physical tactics designed to test defenses, degrade critical infrastructure, and sow fear.

The doctrine's clearest articulation came from the top of Russia's military. As Valeriy Gerasimov, Chief of the General Staff of the Russian Armed Forces, wrote in 2013: "The very rules of war have changed. The role of nonmilitary means of achieving political and strategic goals has grown and, in many cases, they have exceeded the power of force of weapons in their effectiveness."

Insikt Group's bottom line: Russia is likely to escalate NGW tactics over the next two years, potentially culminating in a full-scale NGW campaign. Europe-based private and public sector entities are very likely at risk of physical and cyber sabotage, and critical infrastructure entities are at high risk of being targeted—potentially resulting in data loss, physical damage to facilities, or injury or death of personnel.

The evidence: a year of drones, fires, and firewalls

This isn't speculation built on a single incident. Insikt Group documents a pattern spanning arson, airspace violations, undersea cable threats, disinformation, and cyber intrusions.

  • Airspace incursions have spiked. Insikt Group tracked 30 suspected NATO airspace violations between September 2025 and January 2026—compared to 23 across the entire March 2022 to August 2025 window. The most commonly targeted countries have been Poland and Romania, but violations have reached Germany, the UK, Denmark, and Norway.

  • Sabotage drones are carrying military-grade explosives. On the evening of August 4, 2026, an explosive quadcopter struck the wing near the fuel tank of an Antonov An-124 cargo aircraft in Leipzig, Germany—what Insikt Group calls the first instance in Europe of a sabotage drone carrying military-grade explosives near critical infrastructure. On September 1st, the German government publicly blamed Russia for a sabotage plot at Leipzig/Halle Airport, a key logistics hub for German military support to Ukraine, after police recovered drones carrying military-grade hexogen explosives.

  • Physical sabotage is accelerating. Insikt Group observed a four-fold increase in physical sabotage operations between 2023 and 2024, with 2025 holding at that elevated level. The Polish government attributed a May 2024 fire that destroyed the Marywilska 44 shopping center in Warsaw to Russian intelligence services.

  • Cyber operations lean toward access, not noise. Russian cyber activity against European targets has emphasized access-oriented operations—attacks on internet-facing firewalls, VPNs, email services, and web portals—likely intended to enable intelligence collection and long-term access rather than immediate disruption. When Russia does want to make noise, it does: on August 30, 2026, Russia-nexus actors knocked Norwegian government portals offline in what authorities called retaliation for Norway's military support to Ukraine.

Insikt Group's read is that Russian hybrid warfare in Europe has so far been largely opportunistic, despite increasingly aggressive tactics. The worry is what comes next. Putin likely sees fractured European unity and inconsistent United States assistance as a finite window of opportunity ahead of the 2028 U.S. presidential election—a window in which a full-scale campaign would involve more frequent incursions, multiple tactics used concurrently to strain NATO resources, and escalated aggression. Even then, Insikt Group notes, Russia would likely stop short of permanent damage or mass civilian harm to avoid triggering NATO's Article 5 collective-defense clause.

The malware: Lunex puts the doctrine on your desktop

If the Insikt report is the strategic view, new research from the Ontinue Cyber Defense Center is the ground-level one. On September 24th, Ontinue published what it describes as the first public, in-depth binary analysis of the operational tooling behind Lunex, a malware-as-a-service (MaaS) platform—and the through-line to the geopolitics is hard to miss.

The campaign Ontinue reverse engineered targeted Ukrainian-speaking users through a fake CAPTCHA lure, using a four-stage attack chain that begins with a fake CAPTCHA page and culminates in the deployment of a fully-featured command-and-control agent. The stealer binary was compiled on September 12, 2026—just two days before the incident—with supporting infrastructure provisioned shortly beforehand, indicating active development.

What makes Lunex notable isn't a single clever trick, it's the sophistication stacked at every stage.

  • A silent installer – The delivery mechanism instructs the victim to run an msiexec command that silently installs an MSI presenting itself as "Vertification" by "Internal Software"—a deliberate misspelling matching the Ukrainian word in the lure—into a per-user path that requires no administrator privileges and triggers no UAC prompt.

  • Kill the guards before the theft – Before dropping its payload, the loader runs a Bring Your Own Vulnerable Driver (BYOVD) chain that disables kernel-level security monitoring. Ontinue flags this sequencing as unusual: deploying a BYOVD is not uncommon, but it is rarely used before a final-stage payload such as an information stealer. This lets the final payload run after disabling callbacks from multiple endpoint security products. The abused driver is AMD's PDFWKRNL.sys (CVE-2023-20598), whose validly signed certificate chain lets Windows load it even though the file was modified after signing.

  • Surgical, not blunt, EDR evasion – Rather than crudely killing security processes, the loader downloads the Windows kernel's own debugging symbols from Microsoft's official Symbol Server to resolve exact kernel offsets, then uses the vulnerable driver to zero out callback table entries belonging to a 20-entry blocklist of security products. That blocklist is telling: 45% of it targets Russian and CIS antivirus products like Kaspersky and Dr.Web alongside Western EDR—consistent with a commercial tool designed for broad geographic applicability. Ontinue's validated testing found that neither HVCI nor the current Microsoft Vulnerable Driver Blocklist prevents this specific PDFWKRNL.sys variant from loading—a gap that persists despite the driver hash being catalogued in the LOLDrivers project since March 2026.

  • Broad theft – The stealer extracts credentials and data from seven Chromium-based browsers and exfiltrates cryptocurrency wallets; and it goes further than most, handling Chrome's newest App-Bound and ChaCha20-Poly1305 encryption formats, where most publicly documented stealer families stop short.

  • A backdoor that survives cleanup – The persistence mechanism is the part defenders should circle. The stealer establishes persistent remote filesystem access through a PowerShell-based Chrome Native Messaging Host, which operates within Chrome's process context and survives stealer binary deletion, system reboots, and browser restarts. As Ontinue warns, an incident responder who removes the stealer executable but does not audit Native Messaging Host registrations leaves the attacker with full filesystem access through the browser.

The Russian fingerprints

Ontinue assesses with confidence that the activity originates from a financially-motivated, CIS-aligned threat actor, and that the Lunex platform is developed by a Russian-speaking developer or team and sold to multiple independent criminal operators. The evidence is layered: the panel frontend contains over 150 Russian-language UI strings loaded as the default locale—not a translation layer over English—and its language selector lists "Русский" as the primary option. A placeholder in the browser-spoofing configuration uses "ya.ru," Yandex Russia's homepage, as the default target domain—a reference natural only to a Russian-speaking developer. And the infrastructure clusters geographically: the highest concentration of panels, six of the 28 identified, is hosted on UFO Technologies in Krasnogorsk, a satellite city of Moscow.

The platform is also growing fast. First documented through OSINT research by Luke Wilkinson at BlueTeamCoolTeam in June 2026, which identified six active panels across five countries, Lunex had expanded to 28 panels across 13 countries by the time of Ontinue's internet-wide scan. This is not a lone operator; it's a criminal supply chain, with multiple stealer codebases in Rust, C, and .NET connecting to the same panel architecture.