Russia is intensifying its hybrid warfare tactics across Europe, blending cyber and physical operations to support its ongoing invasion of Ukraine. According to Recorded Future, these efforts are carefully crafted to avoid direct military confrontation, instead relying on psychological, cyber, and physical strategies to challenge enemy defenses and disrupt critical infrastructure. Recent incidents include attacks on water and wastewater facilities in Norway and Poland, highlighting the psychological impact of even brief service disruptions. Additionally, Poland's energy infrastructure has been a target, attributed to Russian-aligned actors.
Recorded Future's Insikt Group has documented several influence operations where Russia impersonated European media outlets to spread propaganda, notably using AI-generated content to mimic local news sources in France and Norway. Meanwhile, Russian drones have reportedly breached NATO airspace near Estonia and Romania, with Romanian authorities intercepting a drone near an offshore gas project. This activity is seen as a test of NATO's maritime protocols and a threat to energy infrastructure.
Furthermore, Russia has allegedly attempted to damage cargo infrastructure at a German airport using drones and explosives, along with orchestrating cyberattacks against Norwegian public services. Chelsea Cederbaum from Recorded Future emphasizes the risk to companies closely tied to Ukraine's war effort, especially those involved in logistics or manufacturing specialized components for defense systems.
Russia's hybrid warfare approach, described as 'New Generation Warfare' (NGW), remains in development but could evolve into more coordinated and impactful attacks. According to John Gallagher from Viakoo, these tactics could combine cyber-physical assaults with deepfakes and data corruption. The Insikt Group expects Russian aggression to escalate over the next two years, potentially leading to a comprehensive NGW campaign, particularly if US political dynamics shift. Organizations are advised to strengthen defenses against cyber-sabotage, with a focus on phishing-resistant multifactor authentication.

