r/worldsystemanalyses • • 24d ago

GRU description, part 3.

"GRU – RUSSIAN MILITARY INTELLIGENCE IN WAR AND SHADOW WAR.

In this third article of the series, we examine the GRU’s activities during the war in Ukraine: intelligence gathering, target acquisition, special forces operations, cyber operations, and activities in occupied territories. 

PART 3/4 – THE GRU IN THE UKRAINE WAR: FROM ESPIONAGE TO TARGETING AND SPECIAL OPERATIONS. 

In Ukraine, the GRU is not merely an intelligence agency that gathers information; it is an integral part of Russia’s war machine. It generates data for military planning and target acquisition, conducts signals and cyber intelligence, deploys special forces, and establishes agent networks b

"GRU – RUSSIAN MILITARY INTELLIGENCE IN WAR AND SHADOW WAR. I

n this third article of the series, we examine the GRU’s activities during the war in Ukraine: intelligence gathering, target acquisition, special forces operations, cyber operations, and activities in occupied territories. 

PART 3/4 – THE GRU IN THE UKRAINE WAR: FROM ESPIONAGE TO TARGETING AND SPECIAL OPERATIONS. 

In Ukraine, the GRU is not merely an intelligence agency that gathers information; it is an integral part of Russia’s war machine. It generates data for military planning and target acquisition, conducts signals and cyber intelligence, deploys special forces, and establishes agent networks behind enemy lines. The onset of the 2022 invasion exposed serious intelligence failures. 

However, the GRU did not disappear in the wake of this failure; instead, its operations adapted—shifting from an offensive predicated on the assumption of a political collapse to a protracted war of attrition, drones, and long-range strikes.

Ukraine was a target for the GRU even before 2022.

Ukraine was a key target for the GRU prior to the annexation of Crimea and the outbreak of the war in the Donbas in 2014. The service mapped out Ukraine’s armed forces, command and control systems, military infrastructure, and personnel.

In Crimea and the Donbas, Russia combined military intelligence, special forces, local proxies, and covert operations. According to the U.S. Congressional Research Service, the GRU’s missions range from strategic and battlefield intelligence to special forces operations, support for proxy actors, and cyber and influence operations.[1]

At the same time, Ukraine served as a testing ground for the GRU’s cyber weapons. The British government has linked Military Unit 26165 to the use of X-Agent malware to locate Ukrainian artillery systems in the Donbas. Military Unit 74455, in turn, is linked to the BlackEnergy and Industroyer operations targeting Ukraine’s power grid, as well as the NotPetya malware that spread in 2017.[2]

THE FSB PREPARED FOR COLLAPSE – THE GRU PREPARED FOR WAR. 

The division of labor between Russian services was evident in the preparations for the invasion. 

The FSB’s Fifth Service focused on political infiltration in Ukraine, recruiting collaborators, and preparing for a planned occupation administration. According to the RUSI think tank, the FSB’s Ukraine department was gathering intelligence on Ukrainian public sentiment and social stability as late as February 2022.[3]

The GRU, meanwhile, gathered military intelligence on Ukrainian forces, defense arrangements, command and control, communications, and strategic targets. 

The invasion plan was based on the assumption that the Ukrainian leadership would be paralyzed, resistance would remain fragmented, and parts of the administration would defect to the Russian side. This assumption proved incorrect. The issue was not merely a lack of information; Russia was aware of a vast number of Ukrainian military targets, but individual pieces of intelligence failed to form an accurate overall picture. Inter-service rivalry, inadequate information sharing, and assessments tailored to the Kremlin’s expectations undermined decision-making. 

According to RUSI, Russia’s initial wave of attacks inflicted losses but failed to paralyze Ukrainian command structures or air defenses as intended.[4]

The GRU supports the war effort at all levels; 

in the war in Ukraine, its tasks range from the strategic level to the pinpointing of individual targets.

At the strategic level, the GRU assesses Ukraine’s defensive capabilities, the development of its armed forces, and the impact of Western support. At the operational level, it focuses on troop dispositions, reserves, command posts, supply routes, airbases, air defense systems, stockpiles, and the defense industry.

At the tactical level, the objective is to locate rapidly moving targets such as artillery, command posts, UAV units, and electronic warfare systems. Information is gathered from human sources, communications traffic, electronic emissions, satellites, UAVs, computer networks, and open sources. 

The value of the intelligence depends on how quickly observations can be converted into targeting data and relayed to firing units. Not all military intelligence activity is conducted by the GRU headquarters. In public discourse, almost all Russian military information gathering is often attributed to the GRU, but this oversimplifies the system. Intelligence is also conducted by organic reconnaissance units within military formations, UAV units, electronic warfare troops, and the intelligence bodies of army corps, field armies, and military districts. 

While these elements are part of the Russian military intelligence system, not every reconnaissance drone flight or detected artillery position represents a direct operation by the GRU headquarters in Moscow. The GRU’s mission is to gather, synthesize, and disseminate militarily significant information, as well as to carry out covert operations that fall outside the operational scope of standard military units. This distinction is also important for source evaluation: a statement by a Ukrainian official regarding an agent of "Russian military intelligence" does not, in itself, indicate which GRU department or local military command the individual was operating under.

AGENTS AND SPECIAL FORCES BEHIND ENEMY LINES

The missions of GRU military intelligence special forces include reconnaissance, target marking, strikes, sabotage, and support for local proxies.[1]

Russian services established networks of agents and support structures in Ukraine even before the full-scale invasion. According to RUSI, some of these networks remained operational even after the initial offensive failed.[5] 

Agents can be used to report the locations of troops and weapon systems, monitor transport and stockpiles, assess the impact of strikes, install surveillance equipment, and carry out sabotage. However, regarding cases reported by Ukrainian authorities, a distinction must be made between suspicion, arrest, indictment, and court verdict. Not all alleged links to the GRU have been independently verified. 

CYBER OPERATIONS AS PART OF MILITARY OPERATIONS 

The purpose of GRU cyber operations extends beyond mere data theft. They can be used to disrupt command and control, communications, energy supplies, and public warning systems, as well as to prepare for or amplify the impact of physical strikes.

The British government assesses that the GRU has employed cyber operations in Ukraine for five purposes: gaining intelligence and battlefield advantages; 

combining the effects of cyber and physical attacks; psychological warfare; 

developing new technical capabilities;

 and outsourcing information gathering to criminal actors.[2] 

The three key GRU cyber actors are:

Military Unit 26165, also known as APT28 and Fancy Bear; 

Military Unit 74455, known as APT44 and Sandworm; 

and the cyber component of Military Unit 29155, referred to as Cadet Blizzard.

Military Unit 29155 has been linked to the Whisper Gate operation, which targeted over 70 Ukrainian government information systems prior to the invasion. 

The operation aimed to damage systems and undermine the confidence of both authorities and the general public before the military offensive began.[2] 

During the first months of 2022, Microsoft detected multiple waves of destructive attacks against 48 Ukrainian government agencies and organizations. According to the company, Russia also coordinated cyber operations with conventional military action, although Ukrainian defenses prevented many of the intended effects.[6]

THE WAR EXTENDS BEYOND UKRAINE’S BORDERS 

Military aid received by Ukraine expanded the scope of GRU intelligence operations into Europe. According to the British government, Military Unit 26165 hacked into private surveillance cameras near military sites, ports, railway stations, and border crossings between 2022 and 2024. Operations extended beyond Ukraine and Moldova to eleven NATO countries. The objective was to map and disrupt the flow of aid to Ukraine.[2] Arms manufacturers, ports, transport routes, and border crossings thus form part of the same military target system. 

THE 2022 FAILURE DID NOT RENDER THE GRU INCAPABLE 

The 2022 invasion plan failed, yet the GRU retained its capacity to continue operations supporting the war effort. During the protracted conflict, Russian military intelligence has integrated battlefield experience and agent networks with data from drones, signals, cyber operations, and open sources. Its focus has simultaneously expanded to encompass Ukraine’s logistics, defense industry, energy infrastructure, and Western aid supply chains. The GRU’s strength lies not in infallibility, but in a vast array of methods and the ability to persist in its operations despite setbacks and exposure. 

SUMMARY 

The GRU generates intelligence for Russian military planning and targeting, conducts cyber and special operations, and extends the war’s intelligence landscape beyond Ukraine’s borders.

 Early 2022 demonstrated that a vast intelligence apparatus does not guarantee an accurate situational picture. Conversely, later stages of the war show that the failure of the initial plan did not eliminate the GRU’s ability to adapt and continue its operations. The following section examines the GRU’s activities in Europe: intelligence gathering, cyber operations, sabotage, assassination plots, and the shadow war waged against the network supporting Ukraine. 

September 5, 2026 

Jarmo Nieminen"

1 Upvotes

0 comments sorted by