Visualização normal

Antes de ontemAnalyst
  • ✇bellingcat
  • How to Use AI to Help Find Civilian Harm Miguel Ramalho
    Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine.  As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm.  This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus
     

How to Use AI to Help Find Civilian Harm

25 de Junho de 2026, 10:59

Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine. 

As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm. 

This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus on verifying incidents of civilian harm – not just searching for them. 

This piece documents our methodology, ethical considerations and lessons learned in the hope that others researching similar topics can benefit from our work. 

Open source research into civilian harm is still a relatively new field and it presents many challenges – one of the biggest is organising and sorting through the huge volume of user generated content being produced to find what is relevant. 

Machine learning, a form of artificial intelligence that uses algorithms to identify patterns from large amounts of data and make predictions, can make this task more efficient.

With ongoing conflicts involving large amounts of civilian harm occurring in Sudan, and much of the Middle East, this guide aims to offer those covering these conflicts an example of how machine learning can be used to help find and sort incidents. You can also access the Code Notebook for our model here.

We defined “civilian harm” not just as civilian deaths or injuries resulting from armed conflict, but also the broader and delayed effects on civilians from mental trauma, loss of livelihood, displacement, destruction of infrastructure and more. This definition was informed by the Protection of Civilians book on civilian harm

Initial Telegram Dataset 

Each Telegram post containing civilian harm which had already been manually verified by researchers was used to build an initial dataset of confirmed cases of civilian harm, which data scientists call positive instances. We collected a total of 5,848 unique URLs for these Telegram posts. For our manual collection we reviewed posts on relevant Telegram channels, working through oldest to newest posts each day. Assuming that a given post made it to our geolocated incidents list, it meant the researcher who flagged it also looked at the posts that appeared before and after it on Telegram and did not flag those ones, so we selected the 10 posts surrounding the verified civilian harm post as our additional dataset of posts that did not contain civilian harm. After excluding any deleted or duplicate posts, we ended up with 48,545 non-civilian harm posts, our negative instances

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The choice to overrepresent negative instances aims at better reflecting the real world and increasing data available for model training. 

We enriched each URL with metadata from the Telegram API, such as the time of publication, reactions or textual content. As some of these posts had been deleted, we completed the missing data points with previously preserved versions from our Auto Archiver database, only available for the positive instances.

Feature Engineering

Training a machine learning model requires numerical data, as these models compute a prediction score based on mathematical operations.

We built these by converting raw data from our initial dataset, such as keywords signalling potential civilian harm, into numerical scores (or “features”) that the model could interpret, with the aim of increasing the model’s ability to identify patterns. This process, known as feature engineering, can significantly improve model results because it allows data scientists to suggest explicit context knowledge. 

A full list of features we used to train the model can be found in the code notebook accompanying this piece. Many features were directly inspired by researchers’ input from their experiences manually screening cases of civilian harm by sorting through a set number of Telegram channels and inspecting each post individually.

Several of the features used were directly built from the metadata contained in each Telegram post including media_type, day_of_week; or binary ones: forwarded, edited and reply_to

Other features included engagement information: views, forwards, total_reactions, and even individual features for most used emojis including the reaction_crying_face to count 😭 emoji.

Converting Text to Numbers 

To embed the experience from the manual collection process, researchers put together a list of keywords both in Ukrainian and Russian that, to them, signalled posts likely to  show civilian harm. For instance, “Шахед” and “КАБ” translated to “Shahed” and “Guided aerial bomb” respectively. We created a numerical feature to count their frequency. 

In addition, we included several generic English-language keywords which meaningfully signalled potential civilian harm, such as “injured”, “school affected” and “hospital affected” that were only used for generating semantic similarity scores. 

A semantic similarity score is a calculation used to determine the proximity in meaning between different words and phrases. To get the semantic similarity between the post text and each of our keywords, we represented each in a list of numbers via a Sentence Transformer model, which converts words into numerical representations called vectors that a computer can understand. 

We then calculated the level of similarity between each vector using cosine similarity, one of the most popular methods for measuring similarity between two pieces of text.

Due to how embeddings work, this calculation results in a figure on a scale from -1 (no semantic proximity) to 1 (same meaning). For example, the words “hurt” and “injured” would have a high similarity score, while “residential” and “injured” would have a negative score as the words are not semantically similar. 

Finally, to enable the model to identify the relevance of each post to civilian harm in Ukraine, we used a multilingual text transformer from the BERT family of language models to represent the entire post’s text as a vector of 768 numerical values. This model can efficiently represent text from many languages in a way that captures meaning: the same sentence in different languages will generate similar embeddings, and trained machine learning models can detect patterns in the embeddings. 

It is important to note that for this initial prototype of a civilian harm detection model, we did not include any features derived from media content such as photos and videos, although that would be a logical next step in attempting to improve model performance.

Selecting, Training and Evaluating Models

With 54,393 rows of 893 numerical features each, we selected four machine learning algorithms to train our predictive models. 

We chose Logistic Regression as a baseline algorithm due to its simplicity. We also selected three other “best in class” models, Random Forest, XGBoost, and LightGBM. These choices centred on the interpretability of the models and their ability to work on tabular data of this size. For example, we avoided neural networks due to a lack of interpretability and because those models work best with a larger dataset. 

To genuinely assess the performance of the trained models, we split our dataset into three parts:  

  • A training set – the data the models were trained on (60 percent of the full dataset’s rows)
  • A validation set – used for an intermediary evaluation when tuning model parameters (20 percent of all rows)
  • A test set – hidden for the final performance assessment, so the models were evaluated on unseen data (remaining 20 percent of rows)

We used a stratified split to divide the dataset instead of a random split. This method ensured the proportion of positive instances (i.e. confirmed cases of civilian harm) remained consistent across all three sets at about 11 percent.

To measure the performance of machine learning models, we ran them through the test set and measured the number of correct and incorrect predictions. Models output a likelihood between 0 and 1 that each Telegram post contains civilian harm, and we tried to find a cut-off threshold that leads to a good balance between flagging almost every post (0.1) or flagging very few (0.9). 

There are two main types of evaluation metrics to gauge a model’s prediction power. Recall asserts what fraction of positive instances (i.e. known civilian harm posts) were correctly flagged as such. Precision measures the fraction of posts flagged as civilian harm that are indeed civilian harm posts.

Walber, CC BY-SA 4.0, via Wikimedia Commons.

During the training phase, we tuned the models to maximise average precision (PR-AUC), a metric that summarises precision across all recall levels. While this method also accounts for precision, it prioritises recall, which is preferable for this use case as it steers model selection to reduce the number of civilian harm posts that are skipped. 

The following table sorts models from best to worst PR-AUC against a baseline of a coin-flip predictor. ROC-AUC and F1 are two other evaluation metrics included as sanity checks. Simply put, ROC-AUC measures the probability of ranking two instances, one negative and one positive, correctly; F1 balances precision and recall equally and its best cut-off threshold value.

Model test scores comparison, XGBoost stands out in every relevant metric evaluated. 

From these results, we selected XGBoost as our final model as it had the best scores when compared across all metrics.

Interpreting the Model

Because these models are interpretable, we can understand which features are the most useful when predicting whether a post includes civilian harm. The above table shows the top 10 features that most strongly signal the XGBoost model to make a decision:

  • semantic_keywords_similarity: the semantic proximity between the post text and manually selected keywords “casualties”, “damage” and “civilian harm”
  • bert:  the model was able to discern meaning from the text with the same strength as some of the other features in this list – there are three cases of this in the top 10
  • reaction_crying_face: reactions with crying face emojis on the post
  • group_of_messages: whether a post contains multiple media files
  • keywords_in_text: the number of custom Ukrainian or Russian keywords in the post

These results generally tally with what you might expect when selecting Telegram posts for instances of civilian harm, including that posts that generate a lot of emotional engagement and posts using keywords about civilian harm were among those most likely to contain content related to this topic. Not all models had the same top features as XGBoost. In fact, for the Random Forest model the most important feature was the number of crying face emojis present in a post, a soft pattern highlighted by researchers when this methodology was first imagined.

LLM Results and Comparison

Retroactively, we decided to run a sample of the same test dataset through different large language models (LLMs) to gauge their ability to make these same predictions. 

We aimed to include an LLM-generated score as an extra feature for our trained models, which would be captured as relevant if it correlated with the correct predictions. 

To start, we selected two local models, the 1B and 4B variants of Gemma 3 from Google DeepMind, and two cloud-hosted models, Gemini 2.5 flash and Gemini 3.5 flash. With this selection, we hoped to compare results across a wide range of models’ expected performance. 

We generated a 400-row stratified sample (preserving the same proportion of real civilian harm instances) from the test dataset used for the custom models. For each of the four LLM models, we ran two tests: one where only the Telegram post message was sent, and another including both the message and the engineered features (excluding the text embeddings, as the model had direct access to the text). In the prompt for each model, we asked for a score between 0 and 1. We then evaluated the results as we did for the custom models. 

The above table shows that LLMs can indeed extract value from the engineered features. All four LLMs surpassed the baseline Logistic Regression model in our tests, yet none of them performed better than the other custom-trained models, and XGBoost remained the one with the highest PR-AUC. 

Still, Gemini 2.5 Flash performed better than its newer version 3.5 and even achieved a slightly higher best F1 score than any other model. While this is a good result, for the flagging of civilian harm posts, the PR-AUC remains the crucial metric, as it captures the model’s ability to identify infrequent instances of civilian harm while minimising false positives.

Ethical Considerations

Introducing an instrument of automated decision-making into a process of detecting civilian harm brings inherent ethical questions. These include automation bias, or how humans tend to blindly place faith in machine-generated recommendations; algorithmic bias, or how the results of these models echo the same patterns present in the training data, including under- or over-representation of types of civilian harm. 

The decision to test an automated methodology for this particular project came from the fact that there were limited resources for both steps in the process – the detection of potential civilian harm and its actual verification. Historically, we built an enormous backlog of unverified incidents because a lot of time had to be spent on monitoring the most recent events so that potential evidence would be captured and preserved as soon as possible. 

The automation of this process also reduced the exposure of researchers to a significant amount of unpleasant and distressing visual and text content, reducing the burden of exposure to traumatic content. 

For this project, we tried to ameliorate the ethical challenges with a number of strategies including randomly flagging posts not captured by any model, monitoring which features models relied on to make decisions, and by doing historical comparisons of patterns in data. 

Additionally, as stated above, for this initial prototype of a civilian harm detection model we did not include any features derived from the media content itself. In the future, it would be a logical next step in attempting to improve the model performance, to include the media from the posts – but using AI to review actual media comes with additional ethical challenges such as model bias.

Because of the opaque ownership of many LLM companies and their generative nature, the use of LLMs for an extra feature presented additional ethical challenges including privacy and safety concerns considering the sensitive nature of the data. Our model did not rely on LLMs, though we retroactively ran a sample through it. 

How the Model Fits into the Bigger Picture 

After selecting this model, we created a user interface where researchers could view a list of Telegram posts sorted from most to least likely to contain indications of civilian harm. The user interface was designed for quick triage and integration, where a positive confirmation from researchers would instantly send the post to the Auto Archiver (Bellingcat’s tool for preserving digital content) and then transfer it to ATLOS (our internal collaborative verification platform). Bellingcat staff and volunteers could then manually verify incidents. Researcher input was constantly stored so that this data could be used to improve the model in the future. 

Preliminary feedback indicated that the AI model was useful. Not only were we able to reduce time and harm from scouring through dozens of war reporting Telegram channels, researchers also reported that the stream of new posts being added to the verification backlog were capturing real and diverse cases of civilian harm. 

We recognise this model has much room for improvement and is a work in progress. Even though it can illicit diverse civilian harm posts, further tests and improvements (such as improved feature engineering and continuous evaluation) are needed before it can confidently be deployed.

Despite the focus on civilian harm and Telegram (highly popular in Ukraine and Russia), this pipeline is generic and can be adapted to other conflict monitoring tasks. How easily this can be done does depend on how open the social media platform is and whether it is possible to scrape posts from it. Apart from that, it is easy to incorporate new features and data, and cheap to automatically retrain, test and deploy models as the system receives more human input.  

Looking forward, sorting through overwhelming amounts of data in a conflict will continue to be challenging. Hopefully, this methodology can help newsrooms, conflict monitoring organisations, and others find the balance between ethical considerations and resources in order to carry out open source investigations on civilian harm and human rights violations. 


Editor’s note: This article was updated on July 3, 2026, to include a line outlining that the model described is a work in progress.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post How to Use AI to Help Find Civilian Harm appeared first on bellingcat.

  • ✇bellingcat
  • Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya Bellingcat Investigation Team
    On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18. While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian
     

Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya

12 de Junho de 2026, 05:51

On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18.

While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian ship has been observed delivering what the Ukrainian government describes as “stolen” grain to the country. The previous case involved the Damas Wave which travelled in January of last year to the port of Misrata which is under the control of the UN-recognised Government of National Unity (GNU). In addition to satellite imagery, Bellingcat deployed a new technique that analysed Grumant’s heading data which was contained in AIS information provided by Lloyd’s List Intelligence, to help confirm Grumant’s presence in Feodosia. 

Bellingcat has been tracking smuggled Ukrainian grain shipments as they find new markets, five of the ships we previously identified have since been sanctioned by the EU while another was sanctioned by the US Department of Treasury.

MapLibre | Protomaps© OpenStreetMap contributors

Bosphorus Strait

Grumant transits the Bosphorus Strait in the middle of the night.

Credit: Yörük Işık.

Black Sea

Grumant enters a region of the Black Sea known for GNSS interference, meaning that Grumant’s publicly reported Automated Identification System (AIS) position is unreliable.

Port of Feodosia

On February 15, a high resolution satellite image confirms the ship is docked at the port of Feodosia at berth No. 1 that is used for bulk and metal cargo. Matching features visible include Grumant’s grey decking, its seven hatches and bright yellow front mast. What appears to be leftover grain can be seen under the two port crates, immediately next to the ship.

Credit: Satellite image ©2026 Vantor.

Black Sea

Grumant exits the area of signal interference, meaning that its reported position on ship tracking services is now reliable again. Its AIS messages indicate it is travelling towards the Bosphorus.

Bosphorus Strait

Grumant transits the Bosphorus Strait towards the Sea of Marmara. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık.

Izmir Anchorage

Grumant arrives in Izmir, Turkey on February 23 and anchors off the coast until March 13.

Over the course of three weeks, Grumant never enters the Port of Izmir. It is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Credit: Planet Labs PBC.

Aliağa

Grumant then loiters off the coast of Aliağa, about 50 km from Izmir. It stays here until March 16, never entering the port. It again is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Near Benghazi

Grumant arrives in Libyan waters and stays off the coast of Benghazi until April 1.

Libyan Waters

Grumant briefly leaves the coast of Benghazi, but returns a few days later.

Benghazi

Grumant leaves the anchorage on April 18 and docks at the port of Benghazi where it unloads the grain. The ship was captured in a Vantor satellite image on April 20.

It leaves port on April 23, and heads back towards the Bosphorus.

Credit: Satellite image ©2026 Vantor.

Bosphorus Strait

After spending a few days off the coast of Tuzla, Grumant transits the Bosphorus towards the Black Sea.

Credit: Yörük Işık.

Lloyd’s List Intelligence has previously reported on the expansion of Russia’s grain smuggling operations, beyond the occupied port of Sevastopol to include Feodosia port

According to the Ukrainian activism, journalism and hacker group, Kiborg News, Grumant used deceptive shipping practices to deliver grain to Latakia, Syria in 2024. The report included several of Grumant’s shipping manifests, which showed it had repeatedly exported grain from Occupied Crimea to Syria. 

Heading Data Helps Locate Grumant

It is standard maritime practice that ships broadcast Automatic Identification System (AIS) messages which include a ship’s position, heading, and draught (among other information).

Because of longstanding Global Navigation Satellite System (GNSS) interference in parts of the Black Sea, the position data transmitted by an affected ship’s AIS system is often unreliable.

Between February 7 and February 19, 2026, data from Lloyd’s List Intelligence shows the Grumant transmitted 29 AIS messages, with unreliable positions in the vicinity of Feodosia. We know these positions are unreliable as they are erratic and some of them report the ship as being positioned on land.

Unreliable AIS positions – Grumant’s reported positions between February 7-19, 2026, via Lloyd’s List Seasearcher.

However, according to the IMO, the heading data transmitted by a ship’s AIS system must come from an onboard compass. A compass is unaffected by GNSS interference, meaning it is a more reliable source of information in these conditions.

Over the same dates, all 29 AIS messages reported the ship’s heading as 267 degrees or 268 degrees. The Port of Feodosia has a heading of 267.5 degrees. The close agreement between the ship’s heading and port heading strongly suggests that Grumant was moored at the port between February 7 and February 19, 2026.

We conducted an extra check of the heading data by reviewing satellite imagery available of berth 1 at Feodosia Port, which suggests that the same vessel was present on several days between February 6 and February 18. Imagery on Feb. 6 shows the port was empty in the morning and occupied in the afternoon. Grumant exited the area of GNSS interference on February 21, and berth 1 at the port was captured on satellite image on February 22 and appeared empty. The low resolution satellite imagery is only used as an additional check to see if a vessel is at the berth.

Timeline of open source observations related to Grumant’s presence (tick) or absence (cross) at Feodosia port. Empty entries indicate a lack of available data.
Sentinel-1 timelapse of Feodosia Port, Copernicus Sentinel data 2026. Annotations by Bellingcat.
PlanetScope timelapse of Feodosia Port, Planet Labs PBC. Annotations by Bellingcat.

Bellingcat checked all vessels transmitting AIS in the vicinity of Feodosia Port and found that Grumant was the only one that consistently transmitted a heading matching the Port of Feodosia over the period of interest.

We shared our research with Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran where he focuses on maritime sanctions enforcement and the tracking of illicit shipping. Brown told Bellingcat that while satellite imagery of vessels remained key for identification, when looking for reliable data in a spoofing environment it made sense to look at the various elements of AIS data to try and find some accurate information, despite GNSS spoofing.

“It’s quite standard for the independent gyro compass to be providing the heading […] I think the majority would not [be subject to spoofing] so it’s a good methodology to parse out the particular data and then make some inferences from that.”

“It’s neat to think of what can be derived from data that would otherwise be dirty or wrong. So there’s still some elements of use in there.”

He added that in theory there are probably some compasses that are subject to spoofing as well. 

He told Bellingcat that it was fair to say the heading data of the Grumant supported identification, but stressed the need to cross-reference with other data sources. 

While in this instance it has been possible to use AIS data to help verify the location of Grumant, it is relatively unusual to have access to this information. 

Ships that call to the occupied territories frequently disable their AIS transponders to do so.

This activity, known as “dark port calls”, is a common tactic for those engaging in illicit or sanctioned trades. 

Grumant does not transmit AIS messages from February 8 to 11, but this is the longest gap in data (see diagram above), with intermittent messages coming through after that point.

It is unclear why Grumant continued to transmit AIS during the period it was loading in Feodosia. 

A review of Lloyd’s List Intelligence data from January 2025 shows that on a previous voyage to the Black Sea the Grumant operated “dark” for 59 days.  

Visual Identification

On February 15, 2026, high resolution imagery showed Grumant docked in the Port of Feodosia. We compared it with other recent images of Grumant to confirm the match. 

The ship in the satellite image has a grey-coloured deck, which is uncommon enough for it to stand out. Many bulk carriers have cranes (including the ships we previously covered such as Krasnodar, Zafar and Zaid), Grumant does not have any. It also has seven hatches (openings for the grain) and a bright yellow front mast that matches the mast of Grumant (see the image of it transiting the Bosphorus). We can match the Grumant in the Feodosia image, not only to pictures of the Grumant shot from the ground, but also to the satellite image from Benghazi.

The length and breadth of the ship also matches that of the Grumant; 180 metres by 22.90 metres. 

Above: Image of the Grumant transiting the Bosphorus. (In yellow: the mast, red: the seven hatches, green: four vent masts, two on either side). Credit: Yörük Işık. Middle: Satellite image of the Grumant in Feodosia on February 15, 2026. (Matching elements are denoted in the same way as the image above). Bottom: Grumant captured at Benghazi port on April 20. Credit: Satellite image ©2026 Vantor. Annotations by Bellingcat.

Libya’s Relationship with Russia and Ukraine 

Libya has complicated internal dynamics with essentially two administrations in charge of different parts of the country – the Government of National Unity (GNU) in the west and the Libyan National Army (LNA) in the east.

In recent years, Russia has backed the LNA’s General Khalifa Haftar, based out of Benghazi, in the east of the country. But Jalel Harchaoui, a political scientist specialising in Libya with the Royal United Services Institute (RUSI), stressed that the two sides of this conflict, the LNA and the UN-recognised GNU, are not currently fighting. Instead they are in a flawed, multi-year truce.

Therefore, the east-west divide isn’t as clear-cut as during the civil war. While all shipments going to Benghazi and Tobruk are overseen by the LNA, not all shipments going to the city of Misrata (which is run by the GNU) are meant for the GNU-dominated part of the country. 

Harchaoui told Bellingcat: “the Tripoli government is in some regards pro-Ukraine, but if there’s business that can be done with Russia through the very opaque port of Misrata and all the right people get paid, the business is going to take place.”

That observation is potentially significant given at least one previously tracked vessel that went from occupied Ukraine to Libya docked in Misrata.

This was not the case of the Grumant, however, which arrived in an LNA-controlled part of the country. It is not known from open sources alone if the authorities in Libya or at the port in Benghazi knew the grain carried by Grumant had come from occupied Ukraine.

Bellingcat contacted the Benghazi-based LNA government and representatives of the Tripoli-based GNU government via the Libyan Embassy in The Netherlands. We also contacted the Port of Benghazi, Port of Imzir in Turkey as well as the Ukrainian and Russian authorities. Representatives of the LNA did not respond to requests for comment before publication, nor did the Port of Benghazi or Port of Izmir. The Libyan Embassy in The Netherlands replied to Bellingcat after publication, stating that Benghazi and eastern Libya are not under the authority or administrative control of the Government of National Unity and therefore they are not currently in a position to comment on Bellingcat’s findings.

Ukraine Continues to Pursue the “Shadow Grain Fleet”

“The port of Feodosia, located in the temporarily occupied Autonomous Republic of Crimea, is not under Ukrainian control, and any commercial activity conducted there is illegal,” the Ministry for Development of Communities and Territories of Ukraine and the Ministry of Foreign Affairs of Ukraine told Bellingcat in a joint response. 

They told us the loading of grain exported from the temporarily occupied territories is an illegal act and Russia was using ports as logistics centers to export stolen Ukrainian agricultural products.

“The expansion of such routes to third countries, in particular to North Africa, demonstrates Russia’s ongoing efforts to circumvent international sanctions and monetize resources stolen from the occupied Ukrainian territories.” 

The Ukrainian Ministry of Foreign Affairs sent information about Grumant’s (IMO: 9385879) “illegal activities” to the diplomatic missions in Great Britain, the Republic of Turkey and the Republic of Tunisia over the course of March to May this year, the ministries told Bellingcat. 

Ukraine is continuing to pursue legal action against Russia’s “shadow grain fleet” they told us. For instance, earlier this month a Swedish court approved the transfer of the Russian “shadow grain fleet” vessel CAFFA to Ukraine for investigation after it was arrested in Swedish waters. 

This case has set a new precedent, going beyond sanction and fines previously handed out to such vessels, and allowing for the detention and confiscation of a shadow fleet vessel in European jurisdictions, the ministries said.

According to Russian court documents Grumant’s previous owner Murmansk Shipping Company was dissolved and “Decision/Reshenie” LLC were listed as the International Safety Manager and operator of Grumant. Decision/Reshenie were also listed as the operator of Grumant in another court document, from an unrelated case. 

Bellingcat attempted to contact Decision/Reshenie to ask about Grumant’s grain shipment from Feodisia Port to Benghazi Port, but they had not responded at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık and Bridget Diakun contributed to this report.

Cover image: Planet Lab image shows Grumant anchored off Izmir, Turkey on February 27. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.


The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.

  • ✇Krebs on Security
  • Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks BrianKrebs
    Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequ
     

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

25 de Maio de 2026, 10:21

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russia’s intelligence agencies.

An investigator with the Tax Intelligence and Investigation Service (FIOD), the Dutch financial crimes agency, during the raid. Image: FIOD.

The Dutch daily news outlet de Volkskrant reports that the Dutch financial crime agency FIOD on May 18 arrested a 57-year-old from Amsterdam and a 39-year-old from The Hague, charging them with violating sanctions law by directly or indirectly making economic resources available to EU-sanctioned entities.

The Dutch investigation focuses on Stark Industries, a sprawling hosting provider that materialized just two weeks before Russia invaded Ukraine. As detailed in this May 2024 deep-dive, Stark quickly became the source of massive distributed denial-of-service (DDoS) attacks against European targets, and emerged as a top supplier of proxy and anonymity services that showed up time and again in cyberattacks linked to Russia-backed hacking groups.

That report identified two Moldovan brothers — Ivan and Yuri Neculiti and their company PQHosting — who were providing one of Stark’s two main conduits to the larger Internet. In May 2025, the EU sanctioned PQHosting and the Neculiti brothers for aiding Russia’s hybrid warfare efforts. But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.  News that PQHosting and the Neculiti brothers were about to be sanctioned by the EU leaked in the media nearly two weeks before the sanctions were announced last year. During that time, the Stark network assets were transferred from PQHosting to a new entity called the[.]hosting, under the control of the Dutch entity WorkTitans BV.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad. On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

On May 18, Dutch financial crime investigators arrested Nesterenko and Zinad, and searched three businesses in Enschede and Almere and two data centers in Dronten and Schiphol-Rijk. A statement from the Dutch authorities said they also seized laptops, telephones and more than 800 servers.

A message to the-hosting customers immediately after 800 of its servers were seized by Dutch authorities. The message says that unfortunately data stored on the server has been lost and cannot be recovered.

De Volkskrant said it reviewed data showing WorkTitans and MIRhosting were the most-used networks in pro-Russian attacks on Danish government bodies between November 13 and 19, 2025, the week of Denmark’s municipal elections.

The publication wrote that prior to Nesterenko’s arrest, the MIRhosting founder denied that he knew his servers had been misused by pro-Russian cybercriminals. “He said he had ended all services with the Neculiti brothers when the EU sanctions came into force in May 2025,” and the he “reserved all rights to take action against ‘harmful and incorrect publications,” de Volkskrant wrote.

MIRhosting released a statement saying it has initiated an internal investigation into the alleged facts concerning the elections in Denmark, and that it has temporarily paused services to WorkTitans as a precautionary measure while the matter is being reviewed further.

“Based on our preliminary findings, there are no indications that the services over which we exercise control were actually used to influence the Danish elections,” the statement reads. “No anomalies or spikes were observed in our network traffic during the period mentioned in the publication; had large-scale DDoS attacks occurred, such activity would have been evident. Furthermore, prior to the media publication, we had not received any complaints, abuse reports, or official requests regarding suspicious activities or misuse of our network. Meanwhile, our regular operational activities continue, and our service to our other clients remains fully intact.”

Born in Nizhny Novgorod, Russia, Mr. Nesterenko grew up as a piano prodigy who performed publicly at a young age. In 2004, Nesterenko founded MIRhosting’s parent Innovation IT Solutions Corp., which has the notable distinction of being the company responsible for hosting stopgeorgia[.]ru, a hacktivist website for organizing cyberattacks against Georgia that appeared at the same time Russian forces invaded the former Soviet nation in 2008. That conflict was thought to be the first war ever fought in which a notable cyberattack and an actual military engagement happened simultaneously.

Responding to questions shared via email, Nesterenko said MIRhosting does not support cybercrime, sanctions evasion, or illegal activity, and that the allegations and arrest by Dutch authorities have been extremely harmful to him and his company.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote. “The hardware and customer portfolio had already been transferred to WorkTitans before the sanctions appeared. Closing or damaging a legitimate Dutch infrastructure company will not stop cybercrime, but it will harm many people who have done nothing wrong.”

Far less is public about the 57-year-old Zinad, who reportedly has been keeping a low profile since our story last year. De Volkskrant reported that Zinad blocked access to his LinkedIn account, had gone months without responding to emails, WhatsApp messages and phone calls, and told a colleague that illness was forcing him to lead a somewhat more reclusive life.

Mr. Zinad’s now-defunct LinkedIn profile. It was full of posts for MIRhosting’s services.

Mr. Nesterenko claims Zinad was never an employee of MIRhosting.

“He helped me and MIRhosting with certain business tasks under a normal business-to-business arrangement between companies,” Nesterenko explained.

However, in previous emails to KrebsOnSecurity, Nesterenko carbon copied Mr. Zinad (who had a @mirhosting.com email), explaining that he was part of the company’s legal team. Also, the Dutch website stagemarkt[.]nl lists Youssef Zinad as an official contact for MIRhosting’s offices in Almere.

Mr. Zinad has never responded to requests for comment. Nor did de Volkskrant have any luck tracking him down. The publication said it repeatedly asked Mr. Zinad (referred to here as simply “Z”), but he reportedly avoided every form of contact.

“‘I am unavailable but will respond to your message as soon as possible,’ reads an automated reply on WhatsApp on 2 October 2025,” de Volkskrant reported. “It is the only response de Volkskrant would receive in months. He did not pick up his phone and did not call back. When an acquaintance asked him via LinkedIn to contact the reporter, he blocked access to his LinkedIn page. At an address in Almere where Z.’s personal limited company is registered, no one was present in April. The corner house’s blinds were drawn, and a pile of rubbish bags lay outside next to a container, as if someone had recently left. A neighbour said he knew the man but did not know where he was staying. Z. was later arrested at a residence in Amsterdam.”

How Russia’s War Has Devastated Civilian Life in Ukraine

In the tiny town of Krasnopillia in rural Ukraine, the stillness of the night is shattered by the whine of a Russian drone. Seconds later, a community hospital bursts into flames. Sparks and debris rain down across the skeletons of trees as the fire sends plumes of smoke into the pitch-black sky.

Dozens of people are evacuated, according to local media reports – but as rescuers respond, in what appears to be a double-tap strike, Russian forces hit a shelter where more than 20 patients are huddled, including some with limited mobility. 

The strike in March 2025 comes just hours after a larger regional hospital in the northeastern Sumy governorate is targeted, decimating the primary health facilities serving the small town of Krasnopillia, whose prewar population was around 7,700. Healthcare services for the town “practically ceased” in the wake of the strikes, Olena Pryima, a local school director, told Bellingcat in a phone interview. 

“[The Russians] destroy the infrastructure so that people do not have the opportunity to live and exist normally. You cannot consult a doctor, nothing,” she said. “And now these people who remain, God forbid, the ambulance will not go there, just because the security situation does not allow it.”

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Her own school was among the many buildings destroyed in Russian strikes, and she says it has been impossible to rebuild amid the ongoing war. “We try to heat some accommodations, in spite of everything … especially since this winter is very difficult,” Pryima said. “But we are not talking about rebuilding at all now. We have hope; we are collecting some documents [such as testimonies and damage assessments], since this will end someday – and then we can rebuild something.”

For the past four years, Bellingcat has been documenting and verifying incidents such as these, chronicling the extensive damage to civilian life and infrastructure after the onset of Russia’s full invasion which began in February 2022.  

In over 2,500 cases of civilian harm that we have verified – the vast majority of which occurred on Ukrainian territory, although dozens also took place in Russia – more than 1,100 residential structures were hit. Hundreds of other civilian sites such as schools, playgrounds, fire stations, hospitals, churches, cultural centres, museums, businesses and farms have been impacted too. 

Our data – which includes cases that Bellingcat researchers were able to definitively geolocate using open source evidence, and does not reflect the full extent of civilian harm across Ukraine – pinpoints more than 300 attacks on schools or childcare facilities, 170 hits on healthcare or humanitarian sites, and four dozen incidents targeting food and related infrastructure. 

While many attacks were clustered around four main cities – Kharkiv, Donetsk, Kherson and Kyiv – we documented strikes across all areas of the country. Of the weapons that could be identified through available open source information, cluster munitions were used in more than 100 cases. 

Cluster munitions, which are banned in more than 100 countries (but not Russia or Ukraine), have killed more than 1,200 people since the war began, with Ukraine recording the highest number of annual casualties worldwide from these weapons in 2024 for the third consecutive year, according to the Landmine and Cluster Munition Monitor. 

Bellingcat and members of its volunteer community logged all verified incidents of civilian harm on an interactive TimeMap over a four-year period spanning February 2022 to December 2025. The map is no longer being updated, but it remains online as an archive (and can be seen below). 

An interactive map detailing incidents of civilian harm between February 2022 and December 2025.

Since Russia’s invasion four years ago, the civilian toll in Ukraine has been stark, with around 15,000 killed – including more than 750 children – and 40,600 injured, according to a January 2026 report by the Office of the United Nations High Commissioner for Human Rights. 

An analysis last year by Armed Conflict Location and Event Data (ACLED) found that Russia followed “a persistent pattern of targeting of populated areas … often indiscriminate, other times more deliberate”. 

Related videos from Bellingcat

New apartment complexes are listed for sale on Russian websites. Meanwhile, Ukrainians are struggling to reclaim their homes.

ACLED’s data for the period of February 2022 to late January 2026 highlights thousands of residential strikes across Ukraine, along with more than 750 attacks on healthcare facilities, 1,200 on educational sites, and 2,400 on energy infrastructure. A February 2025 World Bank report says it will take more than US$500bn to rebuild Ukraine. 

These numbers tell only part of the story. While much global media attention has focused on the politics of the Russia-Ukraine war, or highlighted strikes on large urban centres, civilians in remote rural villages have suffered outsized impacts from the destruction of schools, hospitals and cultural institutions – the key threads tying their communities together.

In Verkhna Syrovatka, a small village in Sumy of around 3,800 people, images from the scene of shelling in May 2025 revealed a massive hole in the community’s blue-roofed cultural house. Inside the facility, which once served as a place for rehearsals, children’s classes and folk ensembles, photographs and trophies could be seen amid piles of splintered wood and cracked concrete.

The village’s only school was also impacted, with many of its windows blown out, forcing classes to move online. This devastation reflects a countrywide trend, as UNICEF reports that Ukrainian children are falling behind in core subjects such as reading, maths and science.

Incidents of civilian harm recorder by Bellingcat in Verkhna Syrovatka. Readers can click or tap the dots to learn more about each incident.

Further south, the village of Opytne in the Donetsk region is gradually being erased, amid a series of Russian attacks dating back more than a decade to the 2014 occupation of the Crimean Peninsula. 

The village has changed hands repeatedly in recent years. In December 2022, drone footage revealed large-scale destruction of its residential area, including a medical office, music school and church. According to media reports, perhaps only half a dozen residents remain out of more than 1,000 who lived in the village a decade ago.

Image left shows the village of Opytne in 2021, before Russia’s full invasion (Credit: Airbus/Google Earth Pro). Image right shows the village of Opytne in 2024 (Credit: Maxar/Google Earth Pro).

A couple of months later, in February 2023 in Dvorichna, a rural settlement in the Kharkiv region, Russian forces launched another double-tap strike: as first responders searched for survivors from an earlier attack on the village council building, several emergency vehicles were hit. 

Located just south of the Russian border, Dvorichna has been occupied on and off since 2022. As a result, the village, whose population was roughly 3,500 four years ago, is estimated to house only 80 residents today.

Across Ukraine, the catalogue of horrors is endless. In Pravdyne, a small village in the Kherson region, the prewar population of more than 1,000 people was reported to have dwindled to fewer than 200 by late 2022. Corpses showing signs of torture have been exhumed from garden beds; in one case, residents reportedly buried the bodies of Ukrainian soldiers under slabs of slate to prevent dogs from reaching them. 

Incidents of civilian harm recorder by Bellingcat in Pravdyne. Readers can click or tap the dots to learn more about each incident.

In Sumy Oblast, Russian drone and missile attacks have forced residents to flee homes they inhabited for half a century. In the village of Hroza in northeastern Ukraine, one-fifth of the population died in a single attack while attending the funeral of a soldier, according to local officials.

What may never be calculated are the impacts this brutal conflict will have on future generations.

Incidents of civilian harm recorder by Bellingcat in Hroza. Readers can click or tap the dots to learn more about each incident.

Back in Krasnopillia, the local school director, Pryima says residents have tried hard to stay in what she calls “the zone of resilience”, but it has been a struggle.

“It’s very scary to fall asleep, because you don’t know if you’ll wake up in the morning,” she said, noting that residents live in constant fear of the drones that fly overhead, keenly aware that a bomb may drop at any moment. 

For Ukrainian children, the effects have been especially dire.

“Those children, before the full-scale invasion, were carefree, cheerful – what children should be,” Pryima said. “Those children are no longer there.” 


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post How Russia’s War Has Devastated Civilian Life in Ukraine appeared first on bellingcat.

  • ✇bellingcat
  • How Russia’s Invasion is Impacting Ukraine’s Youth Bellingcat Investigation Team
    Last month, in the dead of a cold Autumn night, residents in the Ukrainian town of Balakliia were woken by the sound of two massive explosions. Social media footage showed apartments ablaze, balconies obliterated and a deep crater smouldering in a parking lot. Three people were killed and 13 injured in the November 17 attack, Ukraine’s State Emergency Services (SES) said. Four of those injured were children, the SES added. A kindergarten, situated just over a hundred metres from one of the
     

How Russia’s Invasion is Impacting Ukraine’s Youth

17 de Dezembro de 2025, 04:07

Last month, in the dead of a cold Autumn night, residents in the Ukrainian town of Balakliia were woken by the sound of two massive explosions.

Social media footage showed apartments ablaze, balconies obliterated and a deep crater smouldering in a parking lot.

Three people were killed and 13 injured in the November 17 attack, Ukraine’s State Emergency Services (SES) said. Four of those injured were children, the SES added. A kindergarten, situated just over a hundred metres from one of the impact sites, was also reported to have suffered damage.

Since the beginning of the full-scale invasion of Ukraine, schools, educational facilities and spaces used by children have repeatedly been damaged in strikes or closed because of them.  

According to the United Nation’s agency for children, UNICEF, many schools remain closed or continue to be disrupted by air raid alarms. Almost one million children have also been forced to study online, UNICEF states.

Balakliia lies in Kharkiv Oblast in the north east of Ukraine. Another Russian strike carried out there earlier in November caused damage near the town’s main square. Located just over 100 metres away was a high school and not far from that a local theatre school. While neither of those facilities appeared to be directly damaged, many other educational institutions have not been so lucky.

Educational Facilities in the Firing Line

A Ukrainian government website (saveschools.in.ua) has been tracking the number of kindergartens, high schools, colleges and universities that have been damaged and destroyed across the country.

At time of publication 3,676 educational facilities have been damaged nationwide and 394 destroyed, according to saveschools.in.ua.

These trends are reflected in social media data collected by Bellingcat.

Since the start of Russia’s full-scale invasion, Bellingcat has been gathering and verifying social media footage showing incidents of civilian harm. 

More than 2,500 incidents have been identified during this period, including attacks on hospitals, power stations, residential buildings and cultural sites. The full dataset is public and can be found here. But this is likely just a fraction of the damage caused across Ukraine as the data only captures incidents recorded and published on social media channels that have been verified.

Amongst this dataset are more than 200 cases of educational facilities that have been damaged or destroyed.

In September this year, for example, social media footage captured the moment a Russian drone hit an administrative building at Kharkiv’s National University of Pharmacy.

As far  back as July 2022, a school for the visually impaired in eastern Kharkiv was hit by Russian rockets, leaving windows smashed and classrooms burned out.

Just a few months before that, footage posted online appeared to show the remains of a missile that hit a school in the town of Merefa, situated around 30 kilometres to the southeast of Kharkiv.

Kharkiv’s Youth Bears Burden

More educational facilities have been damaged or destroyed in Kharkiv Oblast than in any other territory currently held by Ukraine, according to Bellingcat’s dataset and saveschools.in.ua statistics.

In Kharkiv city and its surrounding areas, Bellingcat found and archived footage of at least 26 schools, kindergartens, colleges or universities that have been damaged and destroyed since Russia’s full-scale invasion. A further 36 strikes that impacted areas around educational facilities in Kharkiv but did not directly hit them were also verified and archived by Bellingcat.

Bohdan Levchykov, a 15-year-old teenager, walks by a damaged habitation building in Balakliia, on October 13, 2025. OLEKSII FILIPPOV / AFP

Sustained attacks on educational facilities as well as widespread disruption to studies caused by the war are having a lasting impact on Ukraine’s young people, children’s rights groups say. 

A report from Save the Children earlier this year detailed how attacks on educational facilities had doubled in Ukraine over the course of 2024. The same report found that parents were scared to send their children to school and that many children were being forced to resort to online learning at home.

A 2024 report from UNICEF has found Ukrainian children are falling behind children in other countries across all/multiple subjects including  reading, maths and science.

In Balakliia, journalists from Agence France-Presse (AFP) bureaus in Paris and Kharkiv spoke to teenage student Bohdan Levchykov who said he studies at home and seldom leaves the house. Levchykov also spoke about the impact of losing his father in the early months of the war.

About an hour’s drive to the northwest, in the town of Khorocheve, a psychologist with the non-profit Voices of Children , Maryna Dudbyk, told AFP that the ongoing war means that everyone is living under stress. 

“This has a huge impact on children’s emotional state,” she said.

“We diagnose a lot of fear and anxiety among children. Adolescents suffer from self-harm, suicidal thoughts, and the loss of loved ones.”

Beyond Schools

Other facilities, beyond schools, regularly enjoyed by children have also been impacted by the war, compounding the challenges young people face.

Bellingcat’s dataset found 28 incidents where swimming pools, parks, football pitches, bowling alleys or museums had been impacted in and around Kharkiv. A further 16 incidents were recorded in areas surrounding such facilities. The below interactive shows (in red) incidents where educational or recreational facilities used by young people have been impacted by Russian strikes in and around Kharkiv. The other markers in the map (in purple) detail additional civilian harm incidents Bellingcat has been able to verify. A wider dataset of showing incidents that have impacted areas surrounding educational and recreational facilities can be found here.

Incidents of civilian harm directly affecting schools and childrens’ leisure facilities are highlighted in red.

One video from March this year showed young men playing football scrambling for cover as a drone can be heard overhead before an explosion can be seen.

Although Ukraine’s policymakers are facing many challenges as Russia’s invasion of Ukraine approaches its fifth year,  the mental health of the country’s youth is on their minds.

Oksana Zbitnieva, head of the Interministerial Coordination Center for Mental Health told AFP that “130,000 frontline health professionals—nurses, pediatricians, family doctors—have received certified training as part of a WHO mental health program.” 

Meanwhile, more than 300 “resilience centres” welcome children and parents across the country, with three hundred more expected to be built next year, according to Ukrainian Social Affairs Minister Denys Uliutine. 

New concepts are also being tested and tried.

Children leave an underground school in Kharkiv, on October 16, 2025. OLEKSII FILIPPOV / AFP

In Kharkiv, underground schools – located beneath the streets of the city – are being set up to help bring children back into the classroom.

City authorities told AFP there would be 10 underground schools operational by the end of 2025.

At a school visited by AFP, a rotating system allows it to continue offering children in-person education, even if only for a limited time, each week. The school enables every  child to attend  half a day of their class in-person each week. When the  child returns home they continue their education via remote classes, while another student comes into school for their half day spot. This allows the school to accommodate 1,400 children, including on weekends. 

Yet recent events in Kharkiv highlight that normal life is far from returning, despite recent peace efforts.

At the end of October, a kindergarten in the west of the city was struck by a Russian drone.

Footage from the scene showed panicked parents and disoriented children being carried from away by emergency workers as smoke billowed from the kindergarten.

Despite the scale of the destruction visible in social media footage, only one person (an adult male) was reported to have died during this strike.

For many youngsters in Ukraine, there may be no reclaiming the childhood that war has taken from them.

But Bohdan Levchykov in Balakliia believes there are still things to look forward to.

He told AFP about  the friends he had made online   – including one named Lana who lives more than 400km away in the city of Dnipro- and his  hopes of  meeting them in real life one day.

“I’ve talked about it with my mother,” he told AFP. 

“Maybe our parents can arrange something for us to meet,” he said hopefully.


Eoghan Macguire, Youri van der Weide and Logan Williams contributed to this report for Bellingcat as did Stéphanie Ladel and Olivia Gresham from Bellingcat’s Volunteer Community.

Boris Bachorz reported and conducted interviews for AFP with the help of Natalia Yermak.

A version of this story can be found on the website of the Central European Digital Media Observatory (CEDMO) website.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post How Russia’s Invasion is Impacting Ukraine’s Youth appeared first on bellingcat.

  • ✇bellingcat
  • Russia’s Smuggled Grain Finds New Market in Saudi Arabia Bellingcat Investigation Team
    A joint investigation by Bellingcat and Lloyd’s List has identified Saudi Arabia as the newest country to import grain directly from a Western-sanctioned port in occupied Crimea, as Russia attempts to secure recognition of the Ukrainian territory via a US-led peace plan. Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows the bulk carrier Krasnodar (IMO: 9296781) sailed from Avlita Grain Terminal in Sevastopol to Saudi Arabia on two occasions
     

Russia’s Smuggled Grain Finds New Market in Saudi Arabia

12 de Dezembro de 2025, 09:38

A joint investigation by Bellingcat and Lloyd’s List has identified Saudi Arabia as the newest country to import grain directly from a Western-sanctioned port in occupied Crimea, as Russia attempts to secure recognition of the Ukrainian territory via a US-led peace plan.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows the bulk carrier Krasnodar (IMO: 9296781) sailed from Avlita Grain Terminal in Sevastopol to Saudi Arabia on two occasions between September and November 2025. Bellingcat confirmed Krasnodar’s journeys ended at Saudi Arabia’s King Abdullah Port in September and the Port of Jazan in November.

These journeys show that Saudi Arabia has joined buyers in Iran, Syria, Egypt, Turkey, Venezuela and Houthi-controlled territories in Yemen who are willing to accept what the Ukrainian government describes as “stolen” grain. 

MapLibre | Protomaps© OpenStreetMap contributors

Black Sea

Krasnodar goes dark – an AIS gap lasting more than two weeks begins on August 22.

Occupied Crimea: Port of Sevastopol

Imagery shows Krasnodar docked at Berth 21 of the Avlita grain terminal at the Port of Sevastopol on August 27.

Credit: Planet Labs PBC

Black Sea

Krasnodar turns its AIS back on in the Black Sea, as required to transit the Bosphorus on September 6.

Bosphorus Strait

Krasnodar transits the Bosphorus. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık

Saudi Arabia: King Abdullah Port

Imagery (as well as AIS data) shows Krasnodar docked at the King Abdullah Port. A pile of what appears to be grain is visible to the right of the image on September 18.

Credit: Planet Labs PBC

Bosphorus Strait

Returning via the Suez Canal, Krasnodar transits through the Bosphorus on September 28 with its red paint fully visible, indicating it is not heavily laden.

Credit: Yörük Işık

Black Sea

Krasnodar goes dark – an AIS gap lasting more than one week begins on October 6.

Occupied Crimea: Port of Sevastopol

Satellite imagery shows Krasnodar docked, with its hatches open, at Berth 21 of the Avlita grain terminal on October 8.

Satellite image ©2025 Vantor

Black Sea

Krasnodar turns its AIS back on in the Kerch strait. After a few days loitering in the Kerch strait, it transits through the Bosphorus.

Bosphorus Strait

With no red paint visible and the Plimsoll line near maximum draft, the vessel appears to be fully laden when it transits the Bosphorus on October 26.

Credit: Yörük Işık

Saudi Arabia: Jazan City

AIS data shows Krasnodar docked at Jazan City for Primary and Downstream Industries for seven days. Planet imagery captured it on November 6.

Credit: Planet Labs PBC

After leaving Jazan, Krasnodar returned to the Black Sea via the Bosphorus on November 23.

It stopped transmitting AIS for a third time on November 24 for nine days and has been intermittently transmitting data since.

Krasnodar was again captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. 

Krasnodar captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. Credit: Planet Labs PBC

Petrokhleb-Kuban Denies Visiting Avlita Terminal

Documents accessed on Russia’s federal registry indicate the vessel is leased by Russian firm Petrokhleb-Kuban, a major player in Russian and international grain markets. 

Petrokhleb Kuban told Bellingcat it “categorically denies any allegations of involvement in the theft of grain from Ukrainian regions”.

It added that Petrokhleb-Kuban does not export grain from the Avlita terminal to any country.

“Petrokhleb-Kuban does not operate at the port of Avlita and does not ship grain from there. All grain shipped by Petrokhleb-Kuban is produced by Russian farmers,” a spokesperson said. 

“The vessel Krasnodar follows all widely accepted safety protocols and does not disable its AIS while on passage. The AIS signal in the Black Sea is being jammed by the military due to the ongoing conflict between Russia and Ukraine.”

The spokesperson also said the vessel Krasnodar was loading barley at the port of Kavkaz, “as confirmed by bills of lading and port clearance.”

AIS interference is rampant in the Black Sea, however, instances of jamming typically do not last more than a couple of days. Further, third-party disruptions impact all vessels in one area indiscriminately. 

Bellingcat reviewed the AIS traces of vessels sailing near Krasnodar. In both voyages, Krasnodar was the only vessel in that area that stopped transmitting AIS data for that period of time.  

Bellingcat also checked available Planet Labs PBC and Sentinel-2 satellite imagery covering the grain terminal in Port Kavkaz during the two periods of August and October where Krasnodar has absent or unreliable AIS coverage and found no vessels matching the length of the Krasnodar.

Bellingcat identified Krasnodar in Avlita terminal on three occasions, by cross referencing satellite images of Krasnodar and recent images and video of the ship. Krasnodar was last detected at Avlita terminal in satellite imagery on November 26, again with its AIS switched off.  Krasnodar’s chimney is navy blue in colour, except for a white band on the left, right, and front side of the chimney. The ship’s other features – five grey hatches, four grey cranes, a red deck, a green floor on the bridge, all visually match known images of the ship.

Finally, the ship’s measurements (a total length of 183 metre according to Russia’s shipping registry) matches what we see in satellite images.

Visual Comparison: Images of Krasnodar at Avlita Terminal and other recent images of Krasnodar

The Krasnodar has a dark blue (midnight navy blue) chimney with a white band that runs around the sides and the front of the chimney, leaving the back completely blue.

A close up of the Krasnodar photographed in the Bosphorus on October 26, 2025. Credit: Yörük Işık.

The life boats are immediately to the left and right of the bridge. The boats can also be seen in satellite imagery from Saudi Arabia. The image below shows Krasnodar in Jazan.

Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Credit: Planet Labs PBC.

Satellite imagery also clearly shows the colour of deck (dull red), the floor colour of the bridge (green), the colour of the hatches and the cranes (grey). All of that, as well as the chimney (navy blue with white) can be matched with satellite imagery from Sevastopol that show Krasnodar docked at the Avlita grain terminal.

Left: Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Right: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Credits: Planet Labs PBC and 2025 Vantor.

Five grey hatches and a red deck. The image on the left is from Jazan (November 6). The image on the right is from Sevastopol (October 8).

A close up of the above images. Credits: Planet Labs PBC and 2025 Vantor.

If we zoom in on the bridge, we can also see that the shape and the colour (grey) of the top of the bridge are also a visual match. 

The chimney is not very clearly visible in the image from Jazan but it is clear that the chimney is dark in colour. The image from Sevastopol shows a dark blue chimney with a white band, which was also visible in images and video of Krasnodar.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: A close up of the Krasnodar taken in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık. Annotations by Bellingcat.

We see red on the hull, below the water line, in the Sevastopol satellite image. You can also see it in the image from when the ship transited the Bosphorus. The rest of the hull is dark.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: Krasnodar photographed in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık.

There are no live or historic sanctions on Krasnodar, according to Lloyd’s List Intelligence data.

Saudi Arabia Joins List of Importers of Russia’s Smuggled Grain


Krasnodar’s voyages from Sevastopol to Saudi Arabia demonstrate that Russia is continuing to expand its grain exports from occupied Crimea to new markets as it negotiates to end the war in Ukraine.

Crimea’s occupied ports have become important assets for Moscow, having evolved into key logistics hubs for dark grain exports over the course of the war.

Prior to the full-scale invasion of Ukraine in 2022, the ports in occupied Crimea were used for the small-scale export of grain and scrap metal, mostly to Syria and Turkey.

The occupation of additional territory in Donetsk and Zaporizhia enabled Russia to establish a new supply route, resulting in more grain being shipped south to Crimea for export to international markets.

The Port of Sevastopol and the Avlita grain terminal remain under European, UK and US sanctions. While no UN sanctions specifically target the port, a majority of UN member states have passed resolutions condemning Russia’s invasion of Ukraine and its occupation of Crimea since 2024. 

Ukraine has repeatedly tried to dissuade countries from purchasing shipments loaded with what it describes as “stolen” grain from occupied regions.

In 2023, Iran received its first grain shipments from Sevastopol. In 2024, it was joined by Venezuela, Libya, Egypt and the Houthis, which control territory in Yemen. Last month, Bellingcat revealed that the bulk carrier Irtysh (IMO: 9664976) delivered grain from the Crimean port of Sevastopol to the Houthi-controlled port of Saleef in Yemen despite Western Sanctions. 

Bellingcat and other news outlets have identified a total of eight countries that have imported grain directly from occupied Crimea.

While Saudi Arabia is the latest direct importer from Sevastopol, it is unclear if authorities are aware of the origin of the cargo. 

The grain shipments follow a similar pattern to Russia’s shadow fleet, which moves sanctioned oil barrels. In both cases steps are taken to disguise the origin of the cargo and port of loading.

Most ships calling to Crimea disable their AIS transponders, which is considered a deceptive shipping practice, and fraudulent documents are issued. 

Alona Shkrum, First Deputy Minister for Development of Communities and Territories of Ukraine, told Bellingcat that Ukraine was closely monitoring Russian exports from occupied territories. She said Ukraine had discussed the issue with Saudi Arabia on the sidelines of recent talks at the International Maritime Organisation Assembly.

She told Bellingcat that Ukraine had “received assurances that Saudi authorities are actively counteracting the risks posed by shadow fleet operations and other violations of international maritime law.” 

She added that Ukraine would continue to work with partners to identify and sanction vessels involved in the illegal export of grain from occupied territories. 

Bellingcat contacted both the Saudi Arabian Ministry of Foreign Affairs and the Russian Ministry of Foreign Affairs; neither responded to requests for comment. 

US-Russia Peace Plan and Ownership of Ukraine’s Ports


The US-Russia 28-point peace proposal includes the recognition of Crimea, Luhansk and Donetsk as “de facto” Russian. Ownership of Crimea and the occupied territories bordering the Sea of Azov is critical for securing shipping routes to and from Russia, and these ports play a vital role in supporting economic growth in the region. 

However, the impact of ceding control of this region and the port of Sevastopol to Russia is not mentioned in either the original US draft plan or subsequent amended versions.

Ian Ralby, chief executive of the maritime and resource security consultancy I.R. Consilium said while it was a high priority for Ukraine to ensure access to the grain market through the Black Sea is preserved, Russia is continuing to try to expand its global access to ports. 

“We see that there is a resurgence in Russia’s efforts on port access.”

“As the prospect of potential peace begins to loom, even though it seems to be much farther off than many would want, there is likely to be a renewed focus on the key strategic assets that matter for the future, and the ports have to be foremost among them.” 


Bridget Diakun, Yörük Işık, Youri van der Weide, Peter Barth and Galen Reich contributed to this report.

Cover image: Planet Lab image shows Krasnodar docked at Jazan City, Saudi Arabia on November 6. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post Russia’s Smuggled Grain Finds New Market in Saudi Arabia appeared first on bellingcat.

  • ✇Krebs on Security
  • Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill BrianKrebs
    A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine. The Nerdify homepage. The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to
     

Drones to Diplomas: How Russia’s Largest Private University is Linked to a $25M Essay Mill

6 de Dezembro de 2025, 11:45

A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine.

The Nerdify homepage.

The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to write their term papers? The answer – recasting the business as an AI company – is just the latest chapter in a story of many rebrands that link the operation to Russia’s largest private university.

Search in Google for any terms related to academic cheating services — e.g., “help with exam online” or “term paper online” — and you’re likely to encounter websites with the words “nerd” or “geek” in them, such as thenerdify[.]com and geekly-hub[.]com. With a simple request sent via text message, you can hire their tutors to help with any assignment.

These nerdy and geeky-branded websites frequently cite their “honor code,” which emphasizes they do not condone academic cheating, will not write your term papers for you, and will only offer support and advice for customers. But according to This Isn’t Fine, a Substack blog about contract cheating and essay mills, the Nerdify brand of websites will happily ignore that mantra.

“We tested the quick SMS for a price quote,” wrote This Isn’t Fine author Joseph Thibault. “The honor code references and platitudes apparently stop at the website. Within three minutes, we confirmed that a full three-page, plagiarism- and AI-free MLA formatted Argumentative essay could be ours for the low price of $141.”

A screenshot from Joseph Thibault’s Substack post shows him purchasing a 3-page paper with the Nerdify service.

Google prohibits ads that “enable dishonest behavior.” Yet, a sprawling global essay and homework cheating network run under the Nerdy brands has quietly bought its way to the top of Google searches – booking revenues of almost $25 million through a maze of companies in Cyprus, Malta and Hong Kong, while pitching “tutoring” that delivers finished work that students can turn in.

When one Nerdy-related Google Ads account got shut down, the group behind the company would form a new entity with a front-person (typically a young Ukrainian woman), start a new ads account along with a new website and domain name (usually with “nerdy” in the brand), and resume running Google ads for the same set of keywords.

UK companies belonging to the group that have been shut down by Google Ads since Jan 2025 include:

Proglobal Solutions LTD (advertised nerdifyit[.]com);
AW Tech Limited (advertised thenerdify[.]com);
Geekly Solutions Ltd (advertised geekly-hub[.]com).

Currently active Google Ads accounts for the Nerdify brands include:

-OK Marketing LTD (advertising geekly-hub[.]net⁩), formed in the name of Olha Karpenko, a young Ukrainian woman;
Two Sigma Solutions LTD (advertising litero[.]ai), formed in the name of Olekszij (Alexey) Pokatilo.

Google’s Ads Transparency page for current Nerdify advertiser OK Marketing LTD.

Mr. Pokatilo has been in the essay-writing business since at least 2009, operating a paper-mill enterprise called Livingston Research alongside Alexander Korsukov, who is listed as an owner. According to a lengthy account from a former employee, Livingston Research mainly farmed its writing tasks out to low-cost workers from Kenya, Philippines, Pakistan, Russia and Ukraine.

Pokatilo moved from Ukraine to the United Kingdom in Sept. 2015 and co-founded a company called Awesome Technologies, which pitched itself as a way for people to outsource tasks by sending a text message to the service’s assistants.

The other co-founder of Awesome Technologies is 36-year-old Filip Perkon, a Swedish man living in London who touts himself as a serial entrepreneur and investor. Years before starting Awesome together, Perkon and Pokatilo co-founded a student group called Russian Business Week while the two were classmates at the London School of Economics. According to the Bulgarian investigative journalist Christo Grozev, Perkon’s birth certificate was issued by the Soviet Embassy in Sweden.

Alexey Pokatilo (left) and Filip Perkon at a Facebook event for startups in San Francisco in mid-2015.

Around the time Perkon and Pokatilo launched Awesome Technologies, Perkon was building a social media propaganda tool called the Russian Diplomatic Online Club, which Perkon said would “turbo-charge” Russian messaging online. The club’s newsletter urged subscribers to install in their Twitter accounts a third-party app called Tweetsquad that would retweet Kremlin messaging on the social media platform.

Perkon was praised by the Russian Embassy in London for his efforts: During the contentious Brexit vote that ultimately led to the United Kingdom leaving the European Union, the Russian embassy in London used this spam tweeting tool to auto-retweet the Russian ambassador’s posts from supporters’ accounts.

Neither Mr. Perkon nor Mr. Pokatilo replied to requests for comment.

A review of corporations tied to Mr. Perkon as indexed by the business research service North Data finds he holds or held director positions in several U.K. subsidiaries of Synergy University, Russia’s largest private education provider. Synergy has more than 35,000 students, and sells T-shirts with patriotic slogans such as “Crimea is Ours,” and “The Russian Empire — Reloaded.”

The president of Synergy University is Vadim Lobov, a Kremlin insider whose headquarters on the outskirts of Moscow reportedly features a wall-sized portrait of Russian President Vladimir Putin in the pop-art style of Andy Warhol. For a number of years, Lobov and Perkon co-produced a cross-cultural event in the U.K. called Russian Film Week.

Synergy President Vadim Lobov and Filip Perkon, speaking at a press conference for Russian Film Week, a cross-cultural event in the U.K. co-produced by both men.

Mr. Lobov was one of 11 individuals reportedly hand-picked by the convicted Russian spy Marina Butina to attend the 2017 National Prayer Breakfast held in Washington D.C. just two weeks after President Trump’s first inauguration.

While Synergy University promotes itself as Russia’s largest private educational institution, hundreds of international students tell a different story. Online reviews from students paint a picture of unkept promises: Prospective students from Nigeria, Kenya, Ghana, and other nations paying thousands in advance fees for promised study visas to Russia, only to have their applications denied with no refunds offered.

“My experience with Synergy University has been nothing short of heartbreaking,” reads one such account. “When I first discovered the school, their representative was extremely responsive and eager to assist. He communicated frequently and made me believe I was in safe hands. However, after paying my hard-earned tuition fees, my visa was denied. It’s been over 9 months since that denial, and despite their promises, I have received no refund whatsoever. My messages are now ignored, and the same representative who once replied instantly no longer responds at all. Synergy University, how can an institution in Europe feel comfortable exploiting the hopes of Africans who trust you with their life savings? This is not just unethical — it’s predatory.”

This pattern repeats across reviews by multilingual students from Pakistan, Nepal, India, and various African nations — all describing the same scheme: Attractive online marketing, promises of easy visa approval, upfront payment requirements, and then silence after visa denials.

Reddit discussions in r/Moscow and r/AskARussian are filled with warnings. “It’s a scam, a diploma mill,” writes one user. “They literally sell exams. There was an investigation on Rossiya-1 television showing students paying to pass tests.”

The Nerdify website’s “About Us” page says the company was co-founded by Pokatilo and an American named Brian Mellor. The latter identity seems to have been fabricated, or at least there is no evidence that a person with this name ever worked at Nerdify.

Rather, it appears that the SMS assistance company co-founded by Messrs. Pokatilo and Perkon (Awesome Technologies) fizzled out shortly after its creation, and that Nerdify soon adopted the process of accepting assignment requests via text message and routing them to freelance writers.

A closer look at an early “About Us” page for Nerdify in The Wayback Machine suggests that Mr. Perkon was the real co-founder of the company: The photo at the top of the page shows four people wearing Nerdify T-shirts seated around a table on a rooftop deck in San Francisco, and the man facing the camera is Perkon.

Filip Perkon, top right, is pictured wearing a Nerdify T-shirt in an archived copy of the company’s About Us page. Image: archive.org.

Where are they now? Pokatilo is currently running a startup called Litero.Ai, which appears to be an AI-based essay writing service. In July 2025, Mr. Pokatilo received pre-seed funding of $800,000 for Litero from an investment program backed by the venture capital firms AltaIR Capital, Yellow Rocks, Smart Partnership Capital, and I2BF Global Ventures.

Meanwhile, Filip Perkon is busy setting up toy rubber duck stores in Miami and in at least three locations in the United Kingdom. These “Duck World” shops market themselves as “the world’s largest duck store.”

This past week, Mr. Lobov was in India with Putin’s entourage on a charm tour with India’s Prime Minister Narendra Modi. Although Synergy is billed as an educational institution, a review of the company’s sprawling corporate footprint (via DNS) shows it also is assisting the Russian government in its war against Ukraine.

Synergy University President Vadim Lobov (right) pictured this week in India next to Natalia Popova, a Russian TV presenter known for her close ties to Putin’s family, particularly Putin’s daughter, who works with Popova at the education and culture-focused Innopraktika Foundation.

The website bpla.synergy[.]bot, for instance, says the company is involved in developing combat drones to aid Russian forces and to evade international sanctions on the supply and re-export of high-tech products.

A screenshot from the website of synergy,bot shows the company is actively engaged in building armed drones for the war in Ukraine.

KrebsOnSecurity would like to thank the anonymous researcher NatInfoSec for their assistance in this investigation.

Update, Dec. 8, 10:06 a.m. ET: Mr. Pokatilo responded to requests for comment after the publication of this story. Pokatilo said he has no relation to Synergy nor to Mr. Lobov, and that his work with Mr. Perkon ended with the dissolution of Awesome Technologies.

“I have had no involvement in any of his projects and business activities mentioned in the article and he has no involvement in Litero.ai,” Pokatilo said of Perkon.

Mr. Pokatilo said his new company Litero “does not provide contract cheating services and is built specifically to improve transparency and academic integrity in the age of universal use of AI by students.”

“I am Ukrainian,” he said in an email. “My close friends, colleagues, and some family members continue to live in Ukraine under the ongoing invasion. Any suggestion that I or my company may be connected in any way to Russia’s war efforts is deeply offensive on a personal level and harmful to the reputation of Litero.ai, a company where many team members are Ukrainian.”

Update, Dec. 11, 12:07 p.m. ET: Mr. Perkon responded to requests for comment after the publication of this story. Perkon said the photo of him in a Nerdify T-shirt (see screenshot above) was taken after a startup event in San Francisco, where he volunteered to act as a photo model to help friends with their project.

“I have no business or other relations to Nerdify or any other ventures in that space,” Mr. Perkon said in an email response. “As for Vadim Lobov, I worked for Venture Capital arm at Synergy until 2013 as well as his business school project in the UK, that didn’t get off the ground, so the company related to this was made dormant. Then Synergy kindly provided sponsorship for my Russian Film Week event that I created and ran until 2022 in the U.K., an event that became the biggest independent Russian film festival outside of Russia. Since the start of the Ukraine war in 2022 I closed the festival down.”

“I have had no business with Vadim Lobov since 2021 (the last film festival) and I don’t keep track of his endeavours,” Perkon continued. “As for Alexey Pokatilo, we are university friends. Our business relationship has ended after the concierge service Awesome Technologies didn’t work out, many years ago.”

From School to Battlefield to Grave: How Russian Cossacks drive young people to war

5 de Dezembro de 2025, 08:08

From School to Battlefield to Grave

How Russian Cossacks drive young people to war

This video was posted in April 2024 by Беркут, a student association within a Russian Federal University.

Students, about to leave for an Airsoft competition, stand in military formation outside a campus building.

This is Олег Монин who took Berkut’s oath four months earlier. Through this veiled Cossack Youth Organisation, he trained in combat tactics with returned fighters and transitioned from pretend to real weapons.

Within a year, Oleg abandoned his studies and enlisted in БАРС-15, a Cossack Volunteer Battalion fighting in Ukraine.

By Feb. 10, 2025 Oleg was dead. He died aged 19, less than four months after deployment in Ukraine.

As of February 2025 there were more than 18,500 Cossacks on the front lines in Ukraine and approximately 50,000 in the army reserve.

Cossack societies, organisations, and even military units provide an identity that is indigenous to Russia, Visiting Assistant Professor at Miami University, Dr Marcello Fantoni told Bellingcat.

This identity is “rooted in ‘traditional’ values, martial prowess, military readiness, orthodox religiosity and a culture not influenced by the ‘corrupting’ West,” Fantoni added via email. This is why “education is central to the overall enterprise”.

Oleg’s story demonstrates how the Cossacks drive young people from a school club to a war zone and enable a state-sponsored alternative mobilisation force.

WHO ARE THE RUSSIAN COSSACKS?

The Cossacks played an important role in the formation of the Russian Empire. They lived in communities called hosts on the edges of the empire. They operate under a military hierarchy ruled by a chief, the Ataman. Due to their loyalty to the Tsar, the Cossacks were repressed by the Bolsheviks after 1917.
Credit: Journal “Chronicle of War”, 1915; Nicholas II among officers

When the Soviet Union collapsed in 1991, the Cossacks’ descendants called for a “rebirth”. In 2005, a bill submitted by President Vladimir Putin allowed registered Cossack organisations members to serve in military units and police forces.
Credit: tamvesti.ru

New hosts were created in traditionally non-Cossack lands with a variety of institutions to direct them. In 2018, the government united them in the “All-Russian Cossack Society”. Putin tries to marginalise the traditional Cossack groups, analyst Paul Goble told Bellingcat while the ones “he has created for his own purposes” play a “major role in military and patriotic education”.
Credit: Kremlin

There are 13 registered Cossack Hosts across all of Russia.

Only 8 of Russia’s 83 recognized Federal Subjects do not have a registered Cossack Host.

In 2018, the Black Sea Cossack Host of Crimea entered the register. The peninsula has been under Russian occupation since 2014. The Cossack legacy is also vitally important to Ukrainian identity.

There are new hosts in the occupied Ukrainian territories of Kherson, Zaporizhzhia, Donetsk, and Luhansk.

Russian Cossack organisations have been “very active within the occupied Ukrainian regions,” Dr Fantoni told Bellingcat. They “recruit local residents and then deploy them for cultural and military purposes,” allowing Russia “to contest and even co-opt a central tenet of Ukrainian national identity – Cossackdom,” he said.

The national “All-Russian Cossack Society” VSKO was created in 2018, and in 2019, the State Duma gave Russian President Vladimir Putin exclusive authority to appoint its national Ataman.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov

At the top of the VSKO is Ataman Vitaly Kuznetsov, a Cossack General.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Nikolai Doluda

Kuznetsov was appointed in November 2023, succeeding the first-ever national Ataman – Nikolai Doluda, then 70 years old and a sanctioned individual.

Kuznetsov has also become a leading Cossack interacting with the Russian state.

Credit: Kremlin; Dmitry Mironov and Vitaly Kuznetsov

Including with Dmitry Mironov, assistant to President Putin and Chair of the Council for Cossack Affairs.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Dmitry Chernyshenko

And Deputy Prime Minister of Russia Dmitry Chernyshenko.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Leonid Pasechnik

As well as Leonid Pasechnik, head of the Luhansk People’s Republic. Kuznetsov thanked Pasechnik in June for helping create three Cossack Cadet Corps in the occupied region.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov with Cossack students of the K.G. Razumovsky Moscow State University of Technology

According to Kuznetsov, the VSKO priorities are “development of military Cossack societies in all directions: education, culture, history, and most importantly, youth. Everything through youth.”

EVERYTHING THROUGH YOUTH

Cossack education can be divided into primary, secondary, and tertiary levels, all with the goal of promoting a unified system.

Credit: sestroretsk.com; Cossack kindergarten pupils

At the primary level are the Cossack kindergartens, which compete nationally to be named the best.

Credit: MOU 'Secondary School No. 43 named after V.F. Margelov'; Cossack students

There are Cossack schools and regular schools with a Cossack affiliation. Data from 2022 claim there were just under 2000 such institutions with around 210,000 students, but recent claims point to over 300,000 students.

Credit: shakhty-media.ru; Cossack Cadets

The most intense level of Cossack education is the Cossack Cadets Corps, of which there are 31 across the country, with the newest corps created in Russia’s Far East. They also compete nationally.

Credit: Moscow State University of Technology and Management named after K.G. Razumovsky (PKU); Cossack University graduation ceremony

Finally, the Association of Cossack Universities has 26 members, with many concentrated in Rostov and Krasnodar. There is also a Union of Cossack Youth, which in 2022 had more than 163,000 members. More than 5,500 Cossack youth took part in military exercises on training grounds in 2023.

Oleg’s story demonstrates how young people outside formal Cossack education can still get pulled in. It also shows that the Cossacks are but one of several interlaced strategies for “military-patriotic” education.

Oleg grew up in Saratov.

Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.
Credit: Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.

He studied in Lyceum N.3, a state-funded educational institution in Saratov. Often, the school promotes events like the national Zarnitsa competition. It includes activities like “putting on gas masks” or “sniper games” for third graders.

Credit: Military student club 'Fakel'; Students in military fatigues at an Avangard 24h training.

The school’s military club “Fakel” acts as an intermediary for these events and other nationwide military education initiatives such as the 24-hour-long Avangard training for tenth graders.

Credit: MAOU 'Lyceum No. 3 named after A.S. Pushkin'; School director receives an award for contribution to patriotic education.

In 2024, Natalia Saprykina, the director of Lyceum N.3, was awarded a Letter of Gratitude for her “contribution to the patriotic education of the younger generation” by a Deputy of the Regional Duma.

Oleg graduated from high school in 2023 at the age of 17.

In the same year he enrolled in InPIT, a higher education institution of the Saratov State Technical University.

By November Oleg had turned 18 and was wearing military fatigues and practising survival skills alongside other candidates of a “military-patriotic” student association named Berkut, at another local university, the Saratov State Law Academy (SSLA).

Credit Telegram @infberkut; Photo from Berkut's survival skills training.

Though Berkut is not explicitly a Cossack organisation, we established several connections between the head of Berkut, Alexander Andreevich, and Cossack organisations. As we’ll see, Andreevich was present at multiple military style training camps that Oleg took part in.

Neither Berkut’s VKontakte nor Telegram channel descriptions mention the Cossacks.

Credit: VKontakte @svpo_berkut; Translated screenshot of Berkut's VKontakte description.

Neither does its page in the University website.

Credit: SSLA; Screen grab of Berkut's page in the SSLA website.

The association’s official objectives are “forming a positive image of military service” and “popularisation of service in the Russian army and law enforcement agencies”. It is headed by Alexander Andreevich.

Credit VKVideo @svpo_berkut: Still from one of Berkut's VK videos.

However, some of Berkut’s videos include the banner of a Молодёжная казачья организация.

Credit: Telegram @atamanfetisov; Translated Telegram post by Andrey Fetisov.

A Telegram post by Andrey Fetisov, the Saratov District Ataman, refers to Berkut as a “Cossack Youth Movement”.

Even though Berkut (left) shares a name and eagle iconography with a notorious Ukrainian special police force (right), part of which defected to Russia during the occupation of Crimea in 2014, Bellingcat found no link between the two organisations.

Credit: VKVideo @svpo_berkut; Berkut Logo
Credit: Wikipedia; Emblem of the Berkut special police force of Ukraine.
FROM WAR GAMES TO REAL WEAPONS

By December 2023, nearing the end of the first semester, Oleg and the other candidates took the Berkut oath, making them official members. Oath-taking ceremonies are “invented traditions” among Cossack forces.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Atop the dais stand senior members of Berkut, including the head of the organisation – Alexander Andreevich.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Andreevich is an active Cossack who has been working under the guidance of District Ataman Andrey Fetisov since at least April 2023.

Credit: Instagram @fetisov_; Alexander Andreevich and Andrey Fetisov

More recently, in January 2025, they were both delivering a lesson to Cossack children for Yunarmiya, exemplifying the overlapping network of youth militarisation initiatives.

In July 2025, they both attended Saratov’s Council of Atamans that was hosted at the Ministry of Internal Policy and Public Relations of Saratov. Local organisations often meet there.

Credit: VKontakte Sergey Frolov; Alexander Andreevich and Andrey Fetisov at a Saratov council meeting.

In August 2024, Andreevich attended the iVolga Cossack Youth Festival, where he met Kuznetsov. The only two people featured speaking in an official video.

Credit: VKontakte @svpo_berkut; Alexander Andreevich and Vitaly Kuznetsov at a Cossack Youth Festival

Andreevich also led Oleg to two military-inspired events in April 2024.

The first, on April 13, was the annual Airsoft competition.

Credit: VKontakte War Games: Operation Satellite; Berkut members stand in formation at the Airsoft event
Credit: VKontakte @svpo_berkut; Oleg and other Berkut members inside a training helicopter

Five days later they went to a training that included trench tactics and simulated helicopter jumps.

Credit: VKontakte Alexander Andreevich; Oleg, Andreevich and other Berkut members at Rosgvardia training ground

Since 2023, Oleg often wore a distinctive yellow and red “Скорпион” call sign patch on his chest when wearing military fatigues, which distinguishes him from other youth at the events. That and other distinctive features identify him even with a mask or goggles.

Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK and Telegram posted on 2023-09-10
Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

Bellingcat was able to geolocate this place to be a Rosgvardia training ground on the outskirts of Saratov.

Credit: VKontakte @svpo_berkut; Graphics for the geolocation of training in Rosgvardia training grounds

Notably, the trenches are not visible on Google Earth but are on Yandex Maps, which has more recent imagery for the region.

Credit: VKontakte @svpo_berkut; Trenches photo from Rosgvardia training grounds
Credit: VKontakte @svpo_berkut; Berkut at Rosgvardia training

This group photo tells its own story. The flags visible are, from left to right, for the Volga Cossack Host, the Immortal Regiment, the Kuban Cossack Host, and Veteran News.

Oleg is at the far right wearing his “Scorpion” and Berkut patches.

This time, ex-fighters were there too.

Sergey Frolkov is an ex-fighter in the war on Ukraine. He regularly posts photos with an Akhmat special forces patch, associated with Kadryovites . He is also a member of the local Combat Brotherhood association.

Credit: VKontakte Sergey Frolkov; Cropped photo of Sergey Frolkov

As is Oleg Mysov, another returned fighter who also engages in “patriotic education of youth” events.

Credit: VKontakte Oleg Mysov;Cropped photo of Oleg Misov

Both have attended Cossack events. Even though in this photo they are holding the Volga Cossack Host flag, Bellingcat could not clearly identify them as Cossacks.

A third man, Andrey Berdnikov is indeed a Cossack and a former fighter of BARS-15, the Battalion Oleg joined, though he was reportedly expelled by his Commander. On the left, Alexander Andreevich.

Credit: VKontakte PATRIOT; Cropped photo of Andrey Berdnikov

Bellingcat contacted Sergey Frolkov, Oleg Mysov and Andrey Berdnikov before publication to ask about their roles, but did not receive a response.

Five months later, in September 2024, Oleg went on a two-day training. Andrey Fetisov got a special thanks for the opportunity.

Credit: VKontakte Andrey Fetisov; Photo from the Sep 2024 training featuring Oleg

Bellingcat geolocated it to a military training ground in Samara, the same location where other Cossack recruits trained before deploying to BARS-15. Fetisov himself shared photos of this training ground two weeks after stepping down as Ataman to join BARS-15. Andreevich left and Oleg right in this photo.

Credit: VKontakte Andrey Fetisov; Geolocation graphics with Oleg and Andreevich

They used real weapons this time. A video montage shows participants firing live rounds.

Credit: VKontakte Andrey Fetisov

This is a photo that includes Oleg, Fetisov, and Andreevich. The first media we found for this event is from early September which is consistent with the sun position in this photo and the grass patches seen in satellite imagery from early September 2024.

Credit: VKontakte Andrey Fetisov; Geolocation graphics of photo with Oleg, Andreevich, and Fetisov

Bellingcat contacted Kuznetsov, Fetisov and Andreevich to ask about their roles in the Cossack community, but they haven’t responded.

This is the last time Bellingcat was able to trace Oleg’s whereabouts with open sources before he joined BARS-15.

VOLUNTARY RECRUITMENT

Many countries have a volunteer reserve system for getting more soldiers in times of war. In Russia, the system is known as BARS, created in 2015 and intensified in 2021. All BARS fighters sign a contract with the Ministry of Defense and get paid.

Mapping the geolocated positions of these units in the UAControlMaps Project dataset reveal widespread areas of operations. BARS Battalions are often reorganised. Estimates put the total number so far at over 30 BARS Battalions and 10 of them have overt Cossack affiliation.

Cossacks also operate as detachments in other military structures. By their own reckoning, in February there were more than 18,500 Cossacks on the front lines in Ukraine. In May the first-ever national Ataman, Nikolai Doluda, gave a higher figure of 46,000 Cossacks.

As of 2024, British Professor Rod Thornton estimated that BARS constitute some 10-30,000 troops in Ukraine, 15% of the total invasion force.

The Mediazona project tracks individual Russian losses in Ukraine and publishes bi-weekly reports. As of Nov. 21, 2025, they identified 149,241 publicly named casualties, Oleg among them.

The project also tracks volunteer casualties.

Deaths of volunteer fighters constituted 12.8% of losses in 2022 and 21.9% 2023. In 2024 they more than doubled to 45.7%. As of Nov. 21, verified deaths of volunteer fighters for 2025 were at 42.8%.

BARS-15

BARS-15 is a Cossack battalion created on May 15, 2022, and named Ермак after a historical Ataman. Originally composed of Cossacks from multiple hosts, mainly Volga and Oremburg, it now draws its members from the Volga Host only.
Credit: All-Russian Cossack Society

These are some of BARS-15 specific patches.

Credit: Telegram @bars15ermak; BARS-15 patch
Credit: OK Alexander Cherepanov; BARS-15 patch
Credit: VKontakte Kolya Karbon; BARS-15 patch
Credit: Telegram @izvestia64; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: Rutube SAMARA | 450media; BARS-15 patch
Credit: Telegram @vskoru; BARS-15 patch
Credit: Telegram @vvko_russia; BARS-15 patch

While in BARS-15 Oleg was reportedly assigned to the 15th Separate Guards Motor Rifle Brigade. Several sources place BARS-15 as subordinate to the 15th Separate Guards Motor Rifle Brigade also known as the Black Hussars, headquartered at the Samara Oblast. Bellingcat geolocated this video from September 2024 to their training grounds.

Credit: VKontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

The panel reads Black Hussars. Oleg is on his knee in front of Andreevich, wearing his distinctive “Scorpion” patch.
Credit: VKontakte @svpo_berkut

The number of active Cossack fighters in BARS-15 is reportedly 400, a number echoed by a former Commander, with other sources saying over 900 volunteers have passed through as of September 2024. They reportedly took part in the invasion of Avdiivka among other combat activities in Ukrainian cities both in Donetsk and Luhansk.
Credit: VKontakte @vvko_russia

Bellingcat geolocated this warehouse to the west of Selydove, Donetsk, using satellite imagery and reference images from when the warehouse was a concrete products factory.

Credit: LLC 'Sembiz-1' Selidovsky Reinforced Concrete Plant; Geolocation graphics over crop from facebook image of warehouse
Russia captured Selydove in October 2024. BARS-15 posted from there in January 2025 and June 2025.

One of its former members is Andrey Fetisov, who temporarily stepped down as Saratov District Ataman and joined BARS-15 between approximately November 2023 and June 2024.
Credit: Telegram @izvestia64

The identification of Fetisov’s call sign – СЛЕНГ – suggests he took on military roles such as “Deputy Commander for Educational Work” and “Political Officer”.

In April 2024, Fetisov received a Medal for Bravery from Vitaly Kuznetsov, the national Ataman. Within six months, Fetisov would be taking Oleg to the BARS-15 training camp.
Credit: Telegram @izvestia64

There are many reasons why people are motivated to join Cossack groups, Dr Fantoni told Bellingcat, adding that these motivated individuals “are the driving force” behind militarisation. “Some do it out of patriotic motivations, others for political, economic or individual status gain, some even because this can protect oneself from future mobilisation to an actual fighting unit,” he said.

In the end

Oleg’s connection to the Cossacks was not typical. He did not attend a Cossack school or university and still found himself in their midst via the military youth groups he joined. As his story demonstrates, Cossacks are embedded into the education system. Their involvement includes Berkut showcasing Kalashnikovs to kids in a mall, a teacher and returned BARS-15 fighter weaving camouflage nets with children, a former BARS-15 commander giving inspirational lessons to young students, and Cossack cadets drawing “heartfelt mementoes” to send to BARS-15.

The Russian government announced that funding for the Cossacks will double in the next two years and it continues to implement its Strategy in relation to the Russian Cossacks 2021-2030.

The first-ever national Ataman and Kuznetsov’s predecessor, Nikolai Doluda, is working on a new national law on the Cossacks and the creation of a mobilisational reserve from the Cossacks.

This image first appeared on Oleg’s obituary posted by Fetisov. The vehicle, road, and equipment are consistent with those used by other fighters with the Black Hussars around February 2025.

According to recruitment posts BARS-15 training takes three weeks. A recent study found that to be the norm in Russia’s military while also labelling training as “low-quality and ineffective”.

Oleg’s obituary, published by his University states that “based on the results of training, he was appointed commander of a 120 mm mortar crew”.

Bellingcat reached out to Oleg’s parents.
His mother said she couldn’t speak about Oleg’s death,

it still hurts too much.

Additional research by Timothy B, Afton Briones, Sarah Grossman, Alexandra Malikova, Mitchell Polman, Olivia Gresham, Bonny Albo, Adam Arthur, Robert Chapman of the Bellingcat Volunteer Community.

Youri van der Weide and Aiganysh Aidarbekova contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here. With the unpredictability of social media algorithms making it harder for news outlets to reach audiences consistently, we have also started a WhatsApp channel that you can join to stay updated on our stories.

Satellite images are courtesy of Yandex, Maxar, Airbus, MapBox and Google Earth.

Co-funded by the European Union. Views and opinions expressed are those of the author(s) only and do not necessarily reflect those of the European Union or the European Health and Digital Executive Agency (HADEA). Neither the European Union nor the granting authority can be held responsible for them.

The post From School to Battlefield to Grave<span id="hide-colon">:</span> <span class="subtitle">How Russian Cossacks drive young people to war</span> appeared first on bellingcat.

  • ✇@BushidoToken Threat Intel
  • Tracking Adversaries: Ghostwriter APT Infrastructure BushidoToken
    Introduction to Infrastructure Pivoting Pivoting on infrastructure is a handy skill for cyber threat intelligence (CTI) analysts to learn. It can help to reveal the bigger picture when it comes to malware, phishing, or network exploitation campaigns. Infrastructure pivoting essentially is the act of looking for more systems an adversary has created. The main benefit of this pursuit is the identification of additional targets or victims, more tools or malware samples, and ultimately new insigh
     

Tracking Adversaries: Ghostwriter APT Infrastructure

19 de Janeiro de 2025, 17:06

Introduction to Infrastructure Pivoting

Pivoting on infrastructure is a handy skill for cyber threat intelligence (CTI) analysts to learn. It can help to reveal the bigger picture when it comes to malware, phishing, or network exploitation campaigns. Infrastructure pivoting essentially is the act of looking for more systems an adversary has created. The main benefit of this pursuit is the identification of additional targets or victims, more tools or malware samples, and ultimately new insights about the adversary’s capabilities.

If done correctly, being able to pivot on adversary infrastructure will be very useful during incident response (IR) engagements. For example, it may lead to being able to attribute the intrusion to a known adversary. This will help others during an IR engagement understand the level of threat posed to the victim organisation.

Receiving Threat Data

To be able to pivot on adversary infrastructure, threat data is needed such as the intelligence shared by threat reports put out by various researchers from public and private sector organisations. This scenario, however, involves relying on the analysis skills of other researchers to explain what the infrastructure is and when they observed it in use.

This blog will examine threat data provided by public sector organisations such as the Computer Emergency Response Team of Ukraine (CERT-UA) as well as cybersecurity vendors such as Deep Instinct, Cyble, and Fortinet. These organisations have shared indicators of compromise (IOCs) uncovered following analysis of adversary intrusion activities or upload to online malware sandboxes, such as VirusTotal, among others.

Introduction to the Ghostwriter Campaign

On 3 June 2024, Fortinet shared a report on malicious XLS macro documents leading to Cobalt Strike Beacons. Analysis of the XLS documents showed that they appeared to be targeting the Ukrainian military and linked to a known Belarusian state-sponsored APT group tracked as Ghostwriter (aka UNC1151, UAC-0057, TA445). On 4 June 2024, Cyble also shared a report on a similar campaign.  

In both reports, if the XLS was opened and the macros were executed by the target, a malicious DLL file was downloaded from an adversary-created domain. In Fortinet’s report, two similar “.shop” domains were mentioned. In Cyble’s report another “.shop” domain was also called out.

Overlapping IOCs

The first pivot on Ghostwriter APT infrastructure that will be demonstrated involves finding indicators of compromise (IOCs) such as domains and IP addresses that appear in multiple threat reports.

The fastest way to realize these overlaps is through continuous collection of reported IOCs into a Threat Intelligence Platform (TIP). This will reveal IOCs that appear in multiple threat reports through tagging and sources of where IOCs come from. Eventually, one domain or IP address will get reported by multiple entities and the connection will make itself apparent.

In Figure 1 (see below) the domain “goudieelectric[.]shop” appeared in both Cyble’s blog and Fortinet’s blog. Analysis of all three domains found that they use the same generic top-level domain (gTLD), registrar, and name servers, as well as have a robots.txt directory configured. These common infrastructure characteristics indicate that all three domains were created by the same adversary.

Figure 1. Three similar domains appearing in two threat reports.

Domain Registration & Hosting Overlaps

When more IOCs are reported in other threat reports it is possible to link them to other known domains, this is due to adversaries reusing the same registrars, name servers, and gTLDs.

In Figure 2 (see below), Deep Instinct reported two more domains that could also be linked to the previous three domains through the mutual use of the PublicDomainsRegistry registrar, Cloudflare name servers, and the robots.txt file.

Figure 2. Five similar domains that appear across three threat reports.

Further, CERT-UA reported three more domains (see Figure 3 below) that could be linked to the infrastructure cluster through this same method as well. This pattern of behaviour is a strong indicator that these domains were created by the same adversary.

Figure 3. Eight similar domains that appear across four threat reports.

Finding Unreported Domains

Since the domains from the above threat reports were collected and linked together through overlapping attributes, it is now possible to use these attributes to find more domains that had gone unreported.

Using a VirusTotal domain attribute query, additional domains can be found by using the following registration pattern:

  • Name Servers: CLOUDFLARE
  • Registrar: PublicDomainRegistry
  • TLD: *.shop

This revealed up to 24 domains that matched this pattern that were likely created by Ghostwriter, a state-sponsored APT group:

  • backstagemerch[.]shop
  • bryndonovan[.]shop
  • chaptercheats[.]shop
  • clairedeco[.]shop
  • connecticutchildrens[.]shop
  • disneyfoodblog[.]shop
  • eartheclipse[.]shop
  • empoweringparents[.]shop
  • foampartyhats[.]shop
  • goudieelectric[.]shop
  • ikitas[.]shop
  • jackbenimblekids[.]shop
  • kingarthurbaking[.]shop
  • lansdownecentre[.]shop
  • lauramcinerney[.]shop
  • medicalnewstoday[.]shop
  • moonlightmixes[.]shop
  • penandthepad[.]shop
  • physio-pedia[.]shop
  • semanticscholar[.]shop
  • simonandschuster[.]shop
  • thevegan8[.]shop
  • twisterplussize[.]shop
  • utahsadventurefamily[.]shop

Note: VirusTotal domain searches are only available to VirusTotal Enterprise users. There are other providers which allow you to search for domain registration patterns such as DomainTools, Validin, and Zetalytics. There also some free OSINT sites such as nslookup.io and viewdns.info that can be useful in certain scenarios.

Finding Related Malware Samples

Using the list of similar domains that were uncovered through the registration pattern search, it is then possible to find additional malware samples communicating with them.

This can be achieved by looking at domains in VirusTotal and checking the Relations tab can show communicating files as shown in Figure 4 below.

Figure 4. Additional malware samples uncovered via the VirusTotal relations tab

Using a VirusTotal graph can help to reveal every communicating file with every domain discovered through the registration pattern search, as shown in Figure 5 below.

Figure 5. All communicating files with every additional domain identified.

URL to the VirusTotal Graph: https://www.virustotal.com/graph/embed/gd2c04407d9ba4b75b2ce73d6155d166d3ef75eaf29894ff5ac287c90400072bc?theme=dark

URL to the VirusTotal Collection: https://www.virustotal.com/gui/collection/2aa6b36a717be8bc49f7925434ca40f3ecb9f628414b491da3e985677508ca08/iocs

Lessons Learned

In conclusion, it is important for CTI analysts to closer inspect the attributes of the IOCs they come across. It is not uncommon for state-sponsored APT groups to make such mistakes when creating their infrastructure to launch attacks from. By exploiting this fact, CTI analysts can learn much more about the adversary’s targets, capabilities, and the behaviours of the humans themselves behind such campaigns.

The importance of this type of work was demonstrated in December 2023 when the US Treasury sanctioned members of the Russian APT group known as Callisto (aka Star Blizzard, BlueCharlie, COLDRIVER, GOSSAMER BEAR). The real world identity of Andrey Korinets was revealed after he was sanctioned for fraudulently creating and registering malicious domain infrastructure for Russian federal security service (FSB) spear phishing campaigns.

❌
❌