Microsoft’s fifth annual Digital Defense Report highlights a troubling trend: nation-state actors are teaming up with cybercriminals to launch attacks. This collaboration has resulted in over 600 million potential attacks on Microsoft customers.
The report indicates that these cybercrime gangs are sharing tools and techniques with state-sponsored groups. A significant number of these attacks are occurring in regions affected by conflict, particularly in Ukraine.
According to Microsoft, there is evidence suggesting that Russian threat actors may have hired cybercriminal groups to assist with espionage activities, especially those aimed at Ukraine. For example, in June 2024, a suspected cybercrime group used common malware to compromise at least 50 military devices in Ukraine.
The report also saw that Iranian nation-state actors may have employed ransomware in a campaign aimed at influencing public opinion. They exploited data from an Israeli dating website, offering to remove specific user profiles for a fee.
Microsoft also mentioned a new actor from North Korea that has developed a custom ransomware variant known as FakePenny. This variant was used to target organizations in the aerospace and defense sectors after extracting sensitive data, indicating a focus on both intelligence gathering and profit.

