WarBrief Live | October 6, 2026 | Cyber Intelligence
Behind every headline about Censys Russia Ukraine cyber attacks tracking is a quieter story: researchers mapping the servers, certificates, domains, and compromised devices that state-linked hacking groups rely on. Cyber operations in the Russia-Ukraine war do not run on mystery — they run on infrastructure. And infrastructure leaves traces on the public internet.
This article explains how analysts find and monitor that infrastructure. It is not a lessons-learned piece — our companion analysis, Cyber Warfare in the Russia-Ukraine Conflict: Lessons for Future Conflicts, covers that ground. This is about methodology: the scan data, certificate pivots, and infrastructure reuse that turn one suspicious server into a full picture of an operation.
Key Takeaways
- Researchers track conflict-linked cyber infrastructure through passive internet data — scan results, TLS certificates, passive DNS, and TLS fingerprinting — rather than by touching adversary servers directly.
- Documented cases show the method working end to end: the FBI’s dismantling of the GRU-linked Cyclops Blink botnet (March 2022) and Operation MEDUSA against the FSB-linked Snake network (May 2023).
- Ukrainian defenders use the same playbook: CERT-UA traced a March 2026 phishing campaign to a fake government site and an OVH-hosted command server within days.
- Infrastructure tracking has limits — operators rotate servers fast, attribution is assessment rather than proof, and some operations blend into criminal infrastructure.
What does tracking conflict-linked cyber infrastructure look like in practice?
When Microsoft’s threat intelligence team reported that Russia-aligned actors had launched more than 237 operations against Ukraine starting just before the 2022 invasion — with roughly 40 of them destructive — each of those operations needed somewhere to run. Attackers need command-and-control servers to issue instructions, phishing pages to harvest credentials, and relay points to move stolen data.
“Actors engaging in these attacks are using a variety of techniques to gain initial access to their targets including phishing, use of unpatched vulnerabilities and compromising upstream IT service providers,” said Microsoft VP of customer security and trust Tom Burt.
All of that infrastructure lives on the public internet. Servers answer port scans. TLS certificates are logged in public transparency records. Domains leave registration trails. Analysts stitch these traces together using internet intelligence platforms — including Censys, Shodan, and passive DNS databases — to answer a simple question: what else is this operator running?
See how internet scanning exposed infrastructure in the conflict for background on how scan data reshaped this kind of research.
How does scan data reveal hidden servers?
The core technique is called pivoting. An analyst starts with one known indicator — say, an IP address from a malware sample or a phishing domain — and asks what else shares its fingerprints.
There are several standard pivots. Certificate Transparency logs, searchable through services like crt.sh, show every certificate issued for a domain and all the hostnames listed on it. If one phishing certificate covers five lookalike domains, the analyst just found four more. TLS fingerprints such as JARM capture the distinctive “handshake” behavior of a server’s encryption stack — servers running the same command-and-control framework often share identical fingerprints. Favicon hashes work the same way for web panels: one identical icon can link dozens of servers running the same phishing kit.
Historical scan data matters as much as live data. Operators rotate servers quickly, sometimes within days of exposure. A platform that stores past scan results lets analysts look back at what a server looked like before it was burned — building a timeline of when the infrastructure was set up and how it changed. Censys’s threat-hunting tooling is built around exactly this: certificate and host history visualization to build what it calls “weaponization timelines,” plus pivoting on JARM, JA3, JA4+, and favicon hashes.

For an introduction to the platform itself, see CensysInspect Explained: Internet Intelligence Guide — our explainer on what Censys Inspect is and how internet-wide scanning works.
How Censys Russia Ukraine cyber attacks tracking works: scan data and certificate pivoting in the real world
The method described above is not theoretical. It is the same workflow researchers apply to Russian and Ukrainian cyber operations, and vendors have published walkthroughs of it in action. Censys researchers, for example, documented an investigation in which they identified a network of Russian hosts running Metasploit and PoshC2 frameworks for command-and-control linked to ransomware operations — pivoting on scan data and using host history to expand one lead into a full network view across multiple countries.
The same pivots appear in conflict-linked cases. Consider certificate reuse: when operators issue TLS certificates with distinctive subject names or self-signed characteristics, those certificates become durable fingerprints. In March 2026, Ukraine’s CERT-UA investigated a phishing campaign impersonating the agency itself. The attackers built a fake site at certua[.]tech, and investigators traced the associated command-and-control server to an IP hosted by French provider OVH. The server presented a self-signed certificate created on March 18, 2026, with the organization field set to “TVisor” — a marker that helped tie the pieces together. The attackers even left a note in the fake site’s HTML reading “With Love, CYBER SERP,” and the CyberSerp Telegram channel publicly claimed the attack on March 28, 2026. CERT-UA assigned it the tracking identifier UAC-0255.
This is infrastructure tracking in miniature: domain registration timing, certificate metadata, hosting provider records, and operator mistakes combined into attribution evidence. It took days, not months.
Case study: the Cyclops Blink botnet takedown (2022)
One of the clearest demonstrations of mapped infrastructure being neutralized came in March 2022. The U.S. Department of Justice announced a court-authorized operation against Cyclops Blink, a modular botnet the U.S. government attributed to Sandworm — the GRU-linked group Mandiant later redesignated as APT44.
The botnet’s command-and-control ran on compromised WatchGuard Firebox firewall appliances and ASUS routers — devices sitting at the perimeter of victim networks. The FBI operation, authorized by a court on March 18, copied and removed the malware from the devices used for command-and-control and closed the external management ports Sandworm used to reach them, severing the group’s control.
The existence of Cyclops Blink had been disclosed just weeks earlier, on February 23, 2022, in a joint advisory from the UK’s NCSC and U.S. CISA — issued hours before Russia’s invasion. It was described as the successor to the VPNFilter botnet, which had been sinkholed in May 2018. The episode shows both halves of the cycle: first the infrastructure is found and mapped, then — with legal authorization — it is dismantled.
For more on how scan data exposes this kind of infrastructure before takedowns happen, see our analysis of internet scanning in the conflict.

Case study: Operation MEDUSA and the Snake espionage network (2023)
A year later, the same pattern played out against a very different target. On May 9, 2023, the DOJ announced Operation MEDUSA: the disruption of a peer-to-peer network of computers compromised by “Snake” malware, which the U.S. government attributes to a unit within Center 16 of Russia’s FSB, publicly tracked as Turla.
Snake had been in use for nearly two decades, stealing sensitive documents from hundreds of systems in at least 50 countries — including NATO member governments and journalists. Its peer-to-peer design let infected machines relay commands for each other, making the network resistant to simple blocking.
The FBI spent years analyzing the malware’s communications before developing a tool called PERSEUS that exploited weaknesses in Snake’s authentication to issue commands making the malware overwrite its own vital components. CISA published the technical details in joint advisory AA23-129A. As one DOJ statement put it:
“The Justice Department, together with our international partners, has dismantled a global network of malware-infected computers that the Russian government has used for nearly two decades to conduct cyber-espionage, including against our NATO allies,” said Attorney General Merrick B. Garland.
The Snake case underscores a key point about infrastructure tracking: mapping alone is not the goal. The map is what makes disruption — or long-term monitoring — possible. Turla’s peer-to-peer architecture was specifically designed to defeat IP blocking; only deep protocol-level understanding of the infrastructure enabled the takedown.
What about phishing and espionage infrastructure?
Not all tracked infrastructure is dramatic botnet command-and-control. Much of the daily work is quieter: phishing pages and credential harvesters. This is where the Russia-Ukraine conflict generates some of the richest documented examples.
DomainTools’ investigations team found phishing pages built with Mailu, an open-source mail server, spoofing organizations involved in Ukraine’s defense and telecommunications sectors — companies that had provided support to Ukraine’s military. Separately, Russia-aligned groups tracked as UAC-0050 and UAC-0006 ran spam campaigns through 2025 distributing commodity malware like sLoad, Remcos RAT, NetSupport RAT, and SmokeLoader against governments, defense, energy, and NGOs.
Microsoft’s tracking of Star Blizzard, a group it links to Russia’s FSB, shows how phishing infrastructure scales. Since January 2026, the group ran at least 13 large-scale campaigns; in January and February 2026 it targeted users of the Ukrainian email provider Ukr[.]net with fake tax-audit and fine notices, then extended the same delivery technique to Western governments and financial institutions supporting Kyiv — a progression analysts read as deliberate capability testing.
On the disruption side, ESET’s APT activity reports documented Sandworm’s continued wiper campaigns against Ukraine through 2025: the ZEROLOT wiper deployed against Ukrainian energy companies via abused Active Directory Group Policy, and Sting and ZeroLot wipers used against a Ukrainian university in April 2025. And CERT-UA’s own sector update for July–September 2025 reported an average of 15 incidents per day and more than 150 tracked threat clusters — including the May 2025 “Solntsepyok” attack that hit eight Ukrainian internet providers, and Gamaredon (UAC-0010), which ESET called the most prolific actor targeting Ukraine.
Phishing infrastructure is tracked the same way as everything else: certificate reuse, favicon hashes on phishing kits, hosting patterns, and registration timing. For a deeper look at adversary infrastructure tradecraft, see Tracking Adversary Infrastructure With Censys Data.
What are the limits of infrastructure tracking?
The method has real constraints, and honest research names them.
First, operators rotate. The moment a server is publicly linked to an operation, it may be abandoned. Historic scan snapshots help, but there is always a gap between the map and the present.
Second, attribution is assessment, not proof. When Mandiant calls Sandworm “APT44” and assesses with high confidence that it belongs to GRU Unit 74455, that is a judgment built from many evidence threads — not a mathematical certainty. Vendor assessments can differ, and groups sometimes plant false flags.
Third, the lines blur. Microsoft’s 2025 Digital Defense Report found Russian state-affiliated actors increasingly operating through the cybercriminal ecosystem — renting or buying infrastructure from criminals. When a server is shared between a ransomware crew and a state actor, a scan-data map alone cannot tell you which customer you are looking at.
Finally, passive research has rules. Experienced threat-intelligence teams warn against touching live adversary infrastructure directly — resolving its domains from attributable networks, submitting active samples to public scanners, or scanning it yourself — because each contact tells the operator someone is watching and invites them to rotate or burn your visibility.
Frequently asked questions
How do researchers track the digital infrastructure behind Russia-Ukraine cyber operations?
They combine internet-wide scan data, TLS certificate records, passive DNS, and malware telemetry. Starting from one known indicator — an IP, domain, or certificate — they pivot on shared fingerprints (certificate reuse, JARM TLS fingerprints, favicon hashes, hosting patterns) to uncover related servers, then monitor them over time. See Cyber Warfare Research: Using Internet Scan Data (2026) for the full research-methods walkthrough and How Internet Intelligence Helps Investigate Cyber Attacks for how individual attacks get investigated.
Did Censys identify specific Russian or Ukrainian cyber operations?
Censys publishes threat-hunting tooling and research — including a documented investigation into Russian hosts running Metasploit and PoshC2 command-and-control linked to ransomware — but conflict-specific infrastructure identifications generally come from firms like Mandiant, ESET, and Microsoft, and from Ukraine’s CERT-UA. Scan-data platforms provide the map; the attribution conclusions come from the investigating teams.
What is the difference between Sandworm, APT44, and Seashell Blizzard?
They are different names for the same assessed actor: Mandiant renamed its Sandworm tracking cluster to APT44 in April 2024, assessing with high confidence that it is part of GRU Unit 74455. Microsoft tracks the same group as Seashell Blizzard. CERT-UA uses identifiers like UAC-0082, UAC-0099, and UAC-0113 for related sub-clusters.
Can tracked infrastructure actually be taken down?
Yes, with legal authorization. The FBI’s court-authorized disruption of the Cyclops Blink botnet (March 2022) and Operation MEDUSA against the Snake peer-to-peer network (May 2023) both disabled adversary infrastructure at scale. But takedowns are temporary victories — operators rebuild, and disruption works best when paired with continuous monitoring.
How does critical infrastructure targeting fit into this picture?
Tracking infrastructure is often what reveals targeting intent before an attack lands. Mandiant’s investigation of Sandworm’s October 2022 substation intrusion — from a Neo-REGEORG webshell on an internet-facing server to MicroSCADA commands aimed at tripping circuit breakers — showed OT targeting in progress. See Censys and Critical Infrastructure: Finding Exposed Systems for our coverage of critical infrastructure as a cyber target.
Conclusion
Tracking the digital infrastructure behind Russia-Ukraine cyber operations is fundamentally an exercise in pattern recognition at internet scale. One phishing certificate, one reused TLS fingerprint, one oddly timed domain registration — each is a thread, and researchers pull them until a network emerges. The documented record, from Cyclops Blink to Operation MEDUSA to CERT-UA’s UAC-0255 investigation, shows the method working repeatedly: find the infrastructure, map its reuse, and either monitor it or — with a court order — take it apart.
The operators know this, which is why they rotate fast and borrow criminal infrastructure. The defenders’ edge is persistence: scan data accumulates, certificate histories do not lie, and every rotation leaves a little more of the map filled in. That is why internet intelligence has become a standing capability in this conflict — and why it will remain one wherever state cyber operations run.
Sources and Further Reading
- U.S. Department of Justice — Court-authorized disruption of GRU-controlled Cyclops Blink botnet
- Security Affairs — Operation MEDUSA: U.S. disrupts Russia-linked Snake malware network
- ESET Research — APT Activity Report: Russian cyberattacks in Ukraine intensify (May 2025)
- BankInfoSecurity — Russia’s destructive wiper attacks on Ukraine rise again (Nov 2025)
- Foundation for Defense of Democracies — Russian cyberespionage campaign analysis (Oct 2026)
- The Hacker News — Threat hunting resources, including Censys’s Russian C2 infrastructure research
- Censys — Threat hunting module launch (certificate history, JARM pivoting, CensEye)
- Microsoft — Digital Defense Report 2025