The boundary that does not hold¶
Russia, and the line between service and syndicate
The tidy version of Russian cyber power comes as an organisation chart. On one side the state units: Sandworm and Fancy Bear, both tracked to the GRU, the military intelligence directorate. On the other the criminal syndicates: Conti, Evil Corp, REvil, LockBit, ransomware-as-a-service brands renting out extortion for a cut. Two columns, a line between them, espionage and sabotage filed under the first, profit under the second.
The line is drawn for convenience and does not hold. The Russian case is not a loop, as North Korea did, but a gradient: a spectrum running from directed state operation through tasked-but-independent crew to tolerated free agent, with no clean join anywhere along it. The interesting question is not which column an actor belongs in. It is what the blur permits, and how unevenly the evidence lets anyone locate a given actor on the line.
A capability kept in reserve¶
The substrate here is a large population of skilled operators and a criminal economy the state neither suppresses nor fully employs. Crime is permitted to run, and the rest follows from tolerance more than from command.
A recurring convention is visible in the code itself. Ransomware built in this environment routinely checks the system language or keyboard layout and exits without encrypting if it finds itself on a machine in Russia or the wider Commonwealth of Independent States. The convention is observable but not uniform: many campaigns exclude Russian and CIS environments while pursuing victims abroad, for reasons that may be as much about avoiding local law enforcement as about any explicit protection. What can be said with more confidence sits at the level of tolerance. The US Treasury has described Russia as a haven for ransomware actors, enabling them to operate openly, and separately as having enabled ransomware by cultivating and co-opting criminal hackers while continuing to offer safe harbour. One sanctioned operator, Mikhail Matveev, put the bargain in his own words in public interviews cited by Treasury: his activity would be tolerated by local authorities as long as he stayed loyal to Russia. That is the arrangement described by a participant rather than asserted as a written state rule, which is about as close as the record comes.
Walking the gradient¶
At the directed end, the signature is sabotage that tracks the geopolitical calendar. Sandworm, tied to the GRU, took down parts of the Ukrainian power grid in December 2015 and again in 2016, the first publicly acknowledged blackouts caused by cyberattack, and returned in April 2022 with an Industroyer variant in an ultimately thwarted attempt against high-voltage substations as the invasion got under way. In 2017 the same group released NotPetya through the hijacked update mechanism of a Ukrainian tax-accounting package, a wiper wearing the costume of ransomware: it displayed a ransom note but was built without any means of decrypting what it destroyed. It spread past its Ukrainian target across the world and did damage later estimated in the billions. US prosecutors charged six GRU officers of Unit 74455 with the grid attacks, NotPetya, a hack-and-leak operation against a French presidential campaign, and the Olympic Destroyer attack on the 2018 Winter Games, describing nearly a billion dollars in losses to three identified NotPetya victims alone. None of these operations was primarily a revenue operation. Each is state capability expressed through cyber means.
At the other end sit the crews that exist to make money, and there the state’s hand shows up not as command but as tolerance and occasional reach-in. When a pro-Ukraine insider leaked Conti’s internal chat logs in early 2022, days after the group publicly pledged support to the invasion, the archive read in two registers at once. Much of it is an ordinary software firm: development sprints, difficulty encrypting large files, attempts to obtain demos of endpoint-detection products in order to test evasion, complaints of the kind any payroll produces. Alongside that, researchers reading the logs found references to FSB interest in material the group could reach, including files relating to the imprisoned opposition figure Alexei Navalny and the investigative outlet Bellingcat. What the archive shows is a criminal organisation behaving like a business, and apparent intelligence interest in material it could collect. What it does not show is a chain of command. The public support for the invasion documents an ideological alignment, which is not the same proposition as taking instructions from a service.
The middle of the gradient is where the two registers fuse in one actor. Evil Corp, the group behind the Dridex banking trojan and a succession of ransomware strains, is as commercial as cybercrime gets, charged with theft in the hundreds of millions across dozens of countries. It is also, by the US Treasury’s account, tasked: its leader Maksim Yakubets was described as working since 2017 for the FSB, acquiring confidential documents and conducting operations on the state’s behalf. A later UK National Crime Agency investigation went further, describing the group as tasked to strike NATO targets and shielded from prosecution through a family tie to a former FSB officer. Evil Corp is best read as an investigative label for a changing set of people rather than a stable firm, but across those changes the pattern holds: it does not sit in either column. It is the gradient made into a single organisation.
The strongest evidence against all of this is the state acting against the crime. When Russia arrested alleged REvil members in January 2022, announcing it as a response to a US request, that is Moscow policing the ecosystem it is said to tolerate, and taken at face value it cuts the other way. What weakens it as a counter-example is not that it secretly supports toleration, but that it did not hold: the arrests coincided with a narrow diplomatic opening, no durable prosecution followed, and the activity resumed. Held honestly, it is a mark against toleration that the later record did not sustain. Had the enforcement continued, a porous boundary would be the wrong picture of Russia.
The signature is deniability itself¶
Read across the gradient, the operational signature is not any single technique. It is the utility of the boundary staying blurred. Sabotage that can be disowned, crime that can be leaned on, enforcement that can be performed or suspended: each depends on the state’s relationship to the operator remaining unfixed. The same substrate that lets a criminal crew run for profit lets it be reached when convenient, and the Evil Corp record shows the same relationships that protected a criminal group also enabling the tasking of it. Whether all of this amounts to a deliberately designed architecture, or an accreted set of conveniences that happen to compose one, is a further claim the evidence does not settle.
The Conti archive is the exhibit, in the way a leaked contractor’s paperwork tends to be. The picture it paints is mundane, and the mundanity is the finding: extortion at scale is produced by something structured like an ordinary company, embedded in an economy that permits it, at points apparently useful to a service it is not formally part of. The drama is in the effects. The production is clerical.
What stays open¶
The edge that resists closure here is tasking. It is one thing to show that an operator caused an effect, which indictments, malware analysis and leaked logs can often establish. It is another to show the relationship under which the effect was produced: instructed, encouraged, tolerated, or merely aligned. The evidence separates these unevenly. The Treasury and NCA accounts of Evil Corp assert direct tasking. The Conti logs suggest contact and interest rather than a chain of command. The CIS-exclusion convention demonstrates a shared understanding, not an order. Collapsing all of these into “state-sponsored” flattens exactly the distinction the gradient is made of: demonstrated instruction and permitted freedom are not the same relationship, even when both point the same way.
How these actors get named is the same boundary in another guise. The vocabulary of attribution tends to compress varied relationships into a binary, state-sponsored or criminal, and the personified threat actor, the advanced persistent threat with a number and a nickname, invites the picture of a single directed hand. What the Russian substrate suggests instead is a field of relationships of varying tightness, some of which harden into instruction and most of which do not. The naming conventions are themselves an artefact of the substrate, a way of imposing an organisation chart on a gradient because a chart is easier to indict.
What survives is a single inversion. The porousness of the boundary between Russian state operations and Russian crime is easy to read as weakness, a state that cannot control its own underworld. It reads closer to the opposite. A boundary held firmly would make the relationship easy to classify, producing a capability that is clearly the state’s or a crime that is clearly not. A boundary left porous lets capability, criminality and state interest overlap without having to become the same organisation, each able to borrow the other’s cover. The blur may not be a failure to draw the line. It may be what the line is for.