Cyberattacks against the U.S.: russian intelligence disguises as criminal groups

russia is attempting to gain covert access to U.S. urban infrastructure. This was confirmed by a cyberattack on an American engineering company, carried out by russian state actors using RomCom and SocGholish — intrusion channels typically employed by criminal groups.

▫️The attackers penetrated the company’s systems and obtained data on critical access points and internal processes of contractors working with water supply, transport, and emergency response systems.

▫️The use of SocGholish–RomCom connections blurs the line between cybercrime and russian state operations. The kremlin masks itself as criminal groups to complicate attribution and slow down the response of U.S. intelligence services.

▫️The choice of an engineering company as a target indicates that russia is seeking opportunities to conduct sabotage operations in the U.S. Even failed attacks can provide valuable information on how American defense teams respond.

Each such episode turns U.S. cyberspace into a testing ground where moscow can refine scenarios for future operations against critical infrastructure.

Similar Posts