Russia, China, and Iran are intensifying their collaboration with cybercrime networks to launch a variety of attacks against their adversaries, including the U.S., Microsoft revealed in a report released Tuesday.
The cyberattacks, which ranged from ransomware to phishing, were conducted for purposes of “espionage, destruction, or influence,” with cybercriminal groups in these countries sharing hacking tools and strategies, according to Microsoft’s Digital Defense Report. The report, published on Tuesday, covers cyber threats between July 2023 and June 2024.
In one example, a group affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC) used cyber personas to sell stolen data from an Israeli dating website, beginning last year. Microsoft also uncovered Russian threat actors utilizing new malware and outsourcing some of their cyberespionage efforts to criminal organizations. In June, one such operation compromised at least 50 Ukrainian military devices, likely to extract information for the Russian government.
Microsoft’s report highlighted cyberattacks that sought to influence the U.S. election ahead of November. Russia has continued its efforts to undermine trust in democratic institutions, while Iran and China have ramped up their influence campaigns over the past year. In one instance, Iran operated websites posing as U.S. news outlets, targeting voter groups with divisive content.
Read the Microsoft Digital defense Report here.












