Cyberwar Spikes: Pro-Ukraine ransomware, Pegasus hits Serbia, and a 15,000-machine crypto heist unraveled
A pro-Ukraine hacking collective calling itself VantaCore has targeted at least seven known victims, according to a report published this week by Russian cybersecurity firm F6. The group is described as deploying custom ransomware as part of a broader hybrid-warfare playbook aimed at Russian companies. In parallel, researchers reported the first confirmed Pegasus spyware infection of 2026, along with another spyware variant, found on devices belonging to Serbian student activists and others. Separate reporting from Le Monde says a dozen people, including a parliamentarian and students involved in protests against the government, received notifications suggesting they were targeted by the spyware. These incidents collectively point to a widening “surveillance-and-disruption” ecosystem that blurs state and non-state roles across Europe’s security perimeter. VantaCore’s ransomware campaign benefits Ukraine-aligned actors by creating economic friction and operational uncertainty inside Russia, while also generating plausible deniability through a non-official brand. The Pegasus wave in Serbia raises acute questions about political interference, democratic resilience, and the security posture of civil society under contested information environments. Meanwhile, the dismantling of the Russia-based Sality malware by CrowdStrike and federal authorities—after it allegedly stole crypto for eight years—signals that cybercrime infrastructure can double as strategic intelligence and financial leverage. Market implications are most visible in cyber-risk pricing, incident-response demand, and the liquidity optics around crypto theft. The Sality case involved the covert replacement of copied Bitcoin and Ethereum addresses, and the reported isolation of more than 15,000 infected machines suggests a meaningful reduction in ongoing theft capacity, which can slightly improve sentiment for affected exchanges and custody providers. In the near term, insurers, managed security service providers, and endpoint security vendors may see heightened demand, while ransomware and spyware disclosures typically pressure valuations of exposed firms and raise compliance costs. For crypto markets, even when the direct dollar loss is not specified, address-substitution campaigns can temporarily increase perceived counterparty risk and volatility around on-chain transfers. What to watch next is whether VantaCore’s targeting expands beyond the initially named victims and whether Russian authorities respond with counter-campaigns or new defensive mandates for critical sectors. For Serbia, the key trigger is the scope of Pegasus detections: whether additional activists, journalists, or opposition figures receive notifications, and whether forensic findings lead to legal or parliamentary action. On the Sality front, investors and security teams should monitor whether the takedown yields arrests, infrastructure seizures, and indicators of persistence in the remaining botnet footprint. Across all three stories, the escalation/de-escalation signal will be the cadence of new disclosures, the speed of patching and remediation, and any public attribution that hardens diplomatic positions.
Geopolitical Implications
- 01
Cyber operations are being used simultaneously for economic disruption (ransomware) and political coercion (spyware), increasing pressure on governance and civil society.
- 02
The Serbia Pegasus wave suggests heightened contestation over democratic space and may intensify EU-aligned scrutiny of surveillance governance and security procurement.
- 03
Cross-domain cybercrime infrastructure (Sality) demonstrates how financial theft capabilities can coexist with strategic influence operations, complicating attribution and response.
- 04
If VantaCore’s campaign broadens, Russia may retaliate with counter-cyber measures that spill into European networks and raise compliance costs for multinational firms.
Key Signals
- —New victim lists or additional ransomware variants attributed to VantaCore by independent researchers
- —Forensic confirmation of Pegasus/NoviSpy infections beyond the initial Serbian activist cohort
- —Public statements, legal actions, or parliamentary inquiries in Serbia tied to spyware notifications
- —Whether Sality takedown leads to arrests/seizures and whether residual infrastructure continues to operate
Topics & Keywords
Related Intelligence
Full Access
Unlock Full Intelligence Access
Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.