Full Report
A Bulgarian man and woman detained after a Sept. 3 arson attack in Munich were part of a group linked to Russia’s GRU military intelligence agency that was…
Analysis Summary
# Threat Actor: GRU Special Activities Service (Unit 29155 / Slovak-based Proxy Cell)
## Attribution & Identity
* **Actor identification:** Russian Military Intelligence Agency (GRU), specifically the **Special Activities Service**.
* **Aliases:** Linked to the broader activities of GRU Unit 29155.
* **Known Associations:**
* **Denis Smolyaninov:** Identified as a career GRU officer heading the Leipzig-based operations.
* **Proxy Recruits:** Low-level operatives of various nationalities, including Bulgarians, Latvians, and Ukrainians, acting as "amateur" saboteurs.
## Activity Summary
The actor has recently pivoted toward kinetic sabotage operations across Europe using recruited proxies to maintain deniability. Recent operations mentioned include:
* **Munich Arson (Sept 3, 2026):** Firebombing of a construction site near Rohde & Schwarz and Helsing.
* **Slovakia Sabotage Plot:** A disrupted plan to attack the Skyeton drone manufacturing plant near Prešov.
* **Leipzig/Halle Airport Incident (Aug 4, 2026):** An attempted drone attack involving explosives/incendiary devices.
* **Infrastructure Caching:** Placement of drones and explosives in underground caches for later use by recruited operatives.
## Tactics, Techniques & Procedures
* **Recruitment via Social Media:** Using Telegram to recruit low-level, amateur operatives (non-Russian nationals) to carry out physical attacks.
* **Cryptocurrency Payments:** Using crypto to fund operatives and pay for successful sabotage missions to avoid the traditional financial trail.
* **Kinetic Sabotage:** Use of incendiary devices (molotov-style) and specialized drones (e.g., Gerbera drones) for physical damage.
* **Logistics Networking:** Establishing a trans-European logistics network, specifically using Slovakia as a hub for regional operations.
* **Dead Drops/Caching:** Hiding equipment and drones in underground caches to be retrieved by recruited "low-level" assets.
* **Commercial Shipping Deployment:** Intelligence suggests potential deployment of attack drones from commercial vessels.
## Targeting
* **Sectors:** Defense industry, logistics/transportation hubs (airports), and military manufacturing.
* **Geography:** Germany (Munich, Leipzig, Hamburg), Slovakia (Prešov), and potential threats to France, Spain, and Italy.
* **Victims:**
* **Rohde & Schwarz** (Defense/Electronics)
* **Helsing** (AI/Drone technology for Ukraine)
* **Skyeton** (Drone manufacturing)
* **Leipzig/Halle Airport** (Logistics hub)
## Tools & Infrastructure
* **Malware families used:** N/A (Focus of this report is on physical/kinetic tools).
* **Hardware:**
* **Gerbera Drones:** Potential for use in future attacks.
* **Incendiary Devices:** Improvised devices thrown from vehicles.
* **Drones with Detonators:** Found near Leipzig airport.
* **Infrastructure:** Telegram-based C2 for human assets; Underground caches for physical hardware.
## Implications
The GRU has shifted from traditional espionage to high-risk kinetic sabotage within NATO territory. By using "expendable" foreign proxies recruited online, the GRU lowers the political cost of failure while maintaining pressure on European countries. The strategic goal is to disrupt the supply chain of military aid to Ukraine and create a climate of fear to reduce European support for Kyiv.
## Mitigations
* **Physical Security:** Enhanced surveillance and perimeter protection for defense manufacturers and logistics hubs involved in Ukraine aid.
* **Platform Monitoring:** Increased scrutiny of "work for hire" or "sabotage for hire" recruitment efforts on Telegram.
* **Counter-Drone Systems:** Deployment of mobile anti-drone units and "Cyberdomes" at critical infrastructure (e.g., Leipzig airport).
* **Intelligence Sharing:** Cross-border cooperation within the EU to track the logistics networks (hubs in Slovakia/Latvia) used to move GRU assets.