The Bilateral Cyber War: APT28's Persistent Reach and Ukraine's Offensive Doctrine- 212
June 22, 2026
Western coverage of the Russia-Ukraine cyber conflict follows a predictable asymmetry: Russian attacks are documented, Ukrainian defenses are praised, and the picture that emerges is one of aggressor and defender. The reality is considerably more complex. On one side, Russia's APT28 — the GRU military intelligence unit also known as Fancy Bear — continues to exploit vulnerabilities in Windows infrastructure to penetrate Ukrainian and European systems, demonstrating both technical persistence and an institutional capacity to extract operational value from even partially patched flaws. On the other, Ukraine's military intelligence directorate has been conducting its own offensive operations deep inside Russian military networks — operations that extended, by late 2025, from the eastern front all the way to the African continent. This is not a conflict between a cyber power and its victim. It is a war being fought simultaneously in both directions, across multiple theaters, with consequences that reach well beyond Ukraine's borders.
In January 2026, security researchers at Akamai detected APT28 actively exploiting a previously undisclosed vulnerability in Windows Shell — CVE-2026-21510 — in attacks against Ukraine and European Union countries, a finding subsequently confirmed by Ukraine's Computer Emergency Response Team. The attack chain was carefully constructed: a phishing email, purporting to originate from Ukraine's hydro-meteorological center, delivered a weaponized LNK file that chained two separate vulnerabilities to bypass Microsoft Defender SmartScreen and execute malicious code remotely on the victim's machine. The social engineering layer — impersonating a Ukrainian government meteorological authority — reflected both operational sophistication and intelligence about which communications Ukrainian officials and institutions would treat as credible.
Microsoft patched both vulnerabilities on February's Patch Tuesday. The patch for CVE-2026-21510 was, however, incomplete. While it successfully blocked the initial remote code execution and SmartScreen bypass, it left behind what Akamai researcher Maor Dahan described as a zero-click authentication coercion vulnerability — a gap between path resolution and trust verification that allowed a victim machine to continue authenticating to an attacker's server without any user interaction. "While testing the patch, we noticed something interesting: the victim machine was still authenticating to the attacker's server," Dahan wrote. The residual flaw — CVE-2026-32202 — allowed attackers to capture Net-NTLMv2 authentication hashes, effectively enabling credential theft and lateral network movement without triggering the security controls the February patch was designed to enforce. By late April 2026, both Microsoft and CISA had confirmed active exploitation of the new flaw, with CISA adding it to its Known Exploited Vulnerabilities catalog and setting a May 12 deadline for federal agencies to apply the fix.

The episode illustrates a pattern that has become a structural feature of APT28's operational methodology: the deliberate exploitation of the gap between vulnerability disclosure and effective remediation. When a major vendor patches a flaw under active exploitation, the patch itself becomes an intelligence product — it tells sophisticated actors exactly where the boundary of the fix lies and where the residual attack surface remains. APT28, with the institutional resources of Russian military intelligence behind it, is well positioned to conduct precisely this kind of patch analysis, identifying incomplete fixes faster than most defenders can validate and deploy them. The result is a persistent offensive capability that operates within the patch cycle rather than despite it.
Against this backdrop, Ukraine's Main Intelligence Directorate published a series of statements in late November 2025 that described a fundamentally different kind of operation — one that inverted the typical victim-attacker relationship entirely. Ukrainian intelligence announced that its units had successfully breached networks of secure military communication terminals used by the Russian Armed Forces, penetrating systems not only along the eastern front in Ukraine but in African countries where Russian forces and affiliated units — elements of the former Wagner Group, now operating as Africa Corps — maintain operational presence. The operation combined technical signals interception with human intelligence fieldwork, a hybrid methodology that Ukrainian officials described as essential in the context of high-technology warfare where timely exposure of enemy intentions is operationally decisive.
The strategic logic of the operation followed what might be termed a harvest-then-erase doctrine. Rather than disabling the compromised terminals immediately — which would have alerted Russian commanders and eliminated the intelligence value of the access — Ukrainian units maintained silent collection over an extended period, monitoring command communications and mapping Russian operational intentions across multiple theaters. Only once the intelligence value of continued access was exhausted, or the strategic benefit of disruption outweighed the benefit of continued surveillance, did Ukrainian intelligence authorize public disclosure of the terminals' geolocations and their subsequent kinetic destruction — most likely through long-range drones, artillery, or sabotage operations. The public disclosure was itself an operational gesture: a signal to Russian commanders that their secure communications had been compromised, that the extent of the breach was unknown to them, and that the intelligence collected during the silent phase was already in Ukrainian hands.

The Africa dimension of the operation deserves particular attention. Russian military communications infrastructure on the African continent serves a dual function: coordinating local operations in countries where Russia maintains mercenary or advisory presence, and securing the logistics and resource extraction networks that underpin Russia's economic interests across the Sahel and Central Africa. Ukrainian intelligence penetrating these networks does not only affect the battlefield in eastern Ukraine — it reaches into the broader architecture of Russian power projection on a second continent, complicating Moscow's ability to coordinate operations that it regards as strategically important and largely insulated from the Ukrainian conflict. That Ukrainian military intelligence has both the technical capability and the operational reach to conduct such operations suggests a significant evolution in Ukraine's offensive cyber posture since the full-scale invasion began in 2022.
Read together, these two threads — APT28's exploitation of Microsoft's patch failures in Europe, and Ukraine's penetration of Russian military networks from the front line to West Africa — describe a cyber conflict that has long since escaped the geographic boundaries of Ukraine. It is a war conducted in server farms, signals intelligence nodes, and communication terminals across multiple continents, in which the line between military and civilian targets, between intelligence collection and combat enablement, and between digital and physical consequences has effectively ceased to exist.