21 September 2026

Everything, Everywhere, All at Once: Russia’s Hybrid Campaign Against Europe, 2026–2030

Euro-Atlantic Center for Resilience | Chris Kremidas-Courtney

Russian military intelligence (GRU) and the FSB are orchestrating a deniable, low-cost hybrid campaign across Europe by leveraging criminal networks, commercial infrastructure, and digital platforms to conduct sabotage and espionage. This convergent threat model utilises encrypted messaging and cryptocurrency to recruit and pay local proxies for physical attacks, including the March 2024 arson of a London humanitarian warehouse.

Following the expulsion of over 750 Russian intelligence officers from European capitals between 2022 and 2024, Moscow adapted by outsourcing kinetic operations to a decentralised criminal market termed 'violence-as-a-service'. Europol's Operational Taskforce GRIMM has identified more than 1,400 individuals linked to these online-recruited networks, which execute tasks ranging from GPS jamming in the Baltic Sea to targeting aviation infrastructure like Leipzig Airport. Deniability remains Moscow's primary objective. Consequently, these highly compartmentalised operations exploit vulnerable economic recruits to bypass traditional Western counter-intelligence frameworks and sustain long-term disruption.

Comment

Russia's transition to a 'violence-as-a-service' model, coordinated by the GRU and FSB, fundamentally challenges Western counter-intelligence frameworks. Traditional state-threat monitoring systems are poorly equipped to track highly compartmentalised, low-level proxies recruited dynamically via Telegram. This reliance on disposable, non-attributable actors allows the GRU to bypass traditional border controls and intelligence tripwires.

The operational mechanism relies on Tether to sustain these distributed GRU networks without physical contact. Specifically, handlers utilise this dollar-pegged stablecoin to distribute rapid payments to amateur operatives, bypassing the SWIFT banking network entirely. Consequently, Europol's Operational Taskforce GRIMM faces a highly resilient, self-substituting adversary that reconstitutes faster than traditional legal and financial sanctions can disrupt.

Strategic Question for Discussion
If the GRU continues to exploit Tether and Telegram for decentralised proxy recruitment, does Europol's Operational Taskforce GRIMM possess the jurisdictional reach to disrupt these networks, or does the counter-intelligence challenge remain fundamentally unresolvable at the national level?
The current trajectory indicates that Europol's Operational Taskforce GRIMM will remain limited by the sovereign boundaries of European law enforcement, whereas GRU-directed networks operate seamlessly across borders. The pattern suggests that as long as platforms like Telegram refuse to cooperate with Western intelligence agencies, state-sponsored proxy networks will easily outpace traditional counter-intelligence interventions. My assessment is that disrupting these operations requires targeting the specific cryptocurrency exchanges facilitating Tether-to-fiat conversions rather than chasing individual, disposable recruits.
Share your assessment in the comments below.