During the first half of 2026, CERT-UA specialists recorded an unprecedented surge in cybercrime targeting Ukrainian infrastructure. According to a report released by the State Service of Special Communications on October 1, 2026, the number of incidents exceeded 3,000. The primary trend of the current year is the use of neural networks to automate attacks, which has allowed Russian hackers to significantly scale the intensity of phishing campaigns and the speed of malware development.

The Aggressor's Technological Toolkit

The use of AI models has become a key lever for cybercriminals, enabling them to generate unique phishing pages tailored to specific regions and social groups. Of particular concern is the active use of legitimate platforms to mask attacks: hackers utilize GitHub, Cloudflare services, and ngrok for clandestine data exfiltration and malware distribution.

Targets and Destructive Operations

Government bodies (37%) and state institutions (22%) remain the primary focus of the adversary. The UAC-0173 group has focused on attacks against TCK (recruitment centers), notaries, and administrative service centers, attempting to tamper with state registry data. Meanwhile, the infamous Sandworm group (UAC-0165) continues its destructive efforts to breach critical infrastructure, including energy and gas transport systems.

Threats to Individuals and the Military

The mobile attack vector has undergone significant changes. Android malware is disguised as essential services, ranging from air raid alert maps to testing systems for military personnel. Experts identify DarkSword as a particularly dangerous tool, which allows the exploitation of vulnerabilities in the iOS operating system via compromised news resources, threatening the privacy of officials and military command.

Contradictory Data

There is a divergence in assessments between official CERT-UA reports and independent experts. While government agencies emphasize the systematic nature of Sandworm-level attacks, third-party researchers point out that low-level AI bots can generate chaotic vulnerabilities that do not always align with the centralized strategy of Russian intelligence services, complicating the attribution of many incidents.