How state-sponsored hacking groups are exploiting the OSS ecosystem to advance strategic objectives

On June 23, 2026, a GitHub account called Xpos587 pushed updates to several unrelated repositories within the same narrow window of time. At the time, it seemed innocuous. But weeks later, researchers at Socket, a software supply chain security firm, traced that account back to a campaign called PolinRider and linked it to North Korean state hackers. By the time Socket published its findings on July 6, the attackers had compromised more than 100 open source packages across four different ecosystems. Some of the affected code carried a backdoor—a hidden way for attackers to get back into a system later. Other packages carried an information stealer (malware designed to quietly pull data, like passwords and files, off an infected computer). Developers installed both, believing they were ordinary, run-of-the-mill packages. Socket later determined the campaign had been running since December 2025, seven months before anyone caught it.

The packages involved in that campaign were open source software (OSS): code that anyone can view, use, and contribute to, usually for free. It underpins most of the digital world, from consumer apps to the systems banks and government agencies run on. Historically, the community behind OSS operated on mutual trust, good-faith collaboration, and open exchange. Anyone could submit a change. A smaller group of maintainers decided what made it into the final product. Nobody had to prove their identity or disclose if they were contributing on behalf of an entity or a nation-state.

Strider examined this trust-based system in a report titled Lying in Wait. For organizations’ security, the report introduced what it calls a contributor-centric risk model. In addition to focusing on what the code does—and potential vulnerabilities or malicious code—the approach adds the dimension of understanding who is behind the code.

A System Built on Trust

State-sponsored hacking groups have spent years working their way into open source communities, using the same openness that makes these platforms function against them. According to Strider’s research, groups like Lazarus Group, tied to North Korea, and Cozy Bear, tied to Russia, have infiltrated software supply chains, stolen sensitive data, and run long-term cyber-espionage operations through open source platforms. GitHub, where most of the world’s open source code is hosted and where millions of developers collaborate daily, has become both a primary target and an unwitting tool for this activity.

These groups do not behave like ordinary, financially motivated cybercriminals. A typical criminal group wants a fast payout, and it will abandon an approach quickly if one isn’t coming. State-backed groups operate on a different timeline. They are directed and funded by government entities pursuing specific strategic goals, allowing them to spend years building credibility inside a project before ever putting that access to use.

A Pattern That Keeps Repeating

Strider’s report walks through several OSS incidents that show this is far from an isolated problem.

In 2024, attackers uploaded malicious packages to the Python Package Index, a central repository that millions of developers pull free code from routinely, disguising malware called JarkaStealer as regular tools and using AI chatbots to help the deception spread. Japanese cybersecurity officials attributed the attack to Lazarus Group—a hacking group linked to North Korea.

The discovery of the Log4Shell vulnerability in Log4j, a widely used logging tool that records what is happening inside an application, exposed a large number of organizations to potential attack because so many unrelated systems depended on the same piece of code. Government agencies and cybersecurity firms observed advanced persistent threat (APT) groups—government-backed hacking teams built for long-term, stealthy access—from the PRC, Iran, North Korea, and Turkey actively exploiting the flaw. The costs were enormous. Experts estimate the vulnerability cost organizations more than $90,000 in incident response support per incident, with total costs across industries reaching into the billions. One U.S. federal agency alone dedicated more than 33,000 staff hours to its response, and more than half of corporate security teams spent weeks or longer remediating the issue. Even more than four years later, 72 percent of affected organizations were still detecting active exploitation attempts.

A third approach relied on patience. An individual using the alias “Jia Tan” started contributing to XZ Utils, a popular open source data compression tool, gradually building trust within the project. In 2024, after maintaining a high level of operational security over a lengthy period and earning co-maintainer status, Jia Tan inserted a malicious backdoor into the software. The identity of Jia Tan, and the nation-state group behind the attack, have still never been identified.

Growth Without Guardrails

According to Strider’s research, OSS adoption by businesses and governments has accelerated faster than the security practices meant to protect it. The transparency, decentralized governance, and volunteer-driven collaboration that made open source successful for decades also make it vulnerable to manipulation by well-resourced groups working on behalf of adversarial governments.

Each of the incidents above followed a different path. A vulnerability in one case, a compromised package in another. But in every one, the code passed the same review process every other contribution passes, and no scan or audit caught what was happening. The attackers had spent time earning a position inside the project, and that standing let their changes go through without a second look.

Security tools have grown considerably more capable at detecting the contents of code. They often flag known vulnerabilities, suspicious patterns, and malware signatures before a package ever reaches production. But Strider’s report argues that traditional software security focuses on the code itself while overlooking the people contributing to it. A scan can tell you a package is clean. It cannot tell you who wrote it, or whether that person has ties to a government with a reason to want the code approved.

Strider built a tool called Open Source Software Search to answer exactly that question. By analyzing contributor behavior, affiliations, and activity patterns across open source platforms, the tool helps organizations uncover hidden risks that traditional vulnerability scans completely miss.

Using OSS Search, Strider examined contributors to two widely used repositories: an AI toolkit that makes it possible to run generative AI models on consumer devices and a Python library used to organize data into tree structures. In both cases, it found individuals with direct ties to sanctioned entities and state-backed institutions, whose contributions were embedded inside code that companies rely on every day.

By: Calder Walton, Strider Advisor and Director of Research for the Intelligence Project at Harvard’s Kennedy School

Opinion for The Cipher Brief

There is a growing perception among long-standing US allies that they need to expand commercial relations with the People’s Republic of China (PRC). A thaw or détente with the PRC brings both rewards, particularly for a sluggish economy like Britain’s, but also major risks. History shows that a superpower can ruthlessly exploit détente with the West.

Economic Security and Intelligence

Economic security and intelligence are nothing new. Before the Second World War, for example, Britain ran a small outfit known as the Industrial Intelligence Centre (IIC). Run by a former MI6 officer, Desmond Morton, the IIC provided a coordination of intelligence on German rearmament and, working with MI5, assessed Britain’s commercial vulnerabilities. British intelligence helped to devise the UK government’s War Book, which set out emergency regulations to protect critical national infrastructure in the event of war. After the Second World War, during the Cold War, it became a staple of British and other western intelligence to assess the size and strength of economies behind the Iron Curtain.

Risky Business

In 1972 President Nixon and his national security advisor, Henry Kissinger, ushered in a policy of détente with the Soviet Union. Its purpose was to further divide the Soviet Union from China. Papers at the Nixon library show that Kissinger was under pressure from British firms, in particular, to open up markets behind the Iron Curtain. Britain was in a dire economic doldrum following an oil shock due to a war in the Middle East.

Kissinger and Nixon knew that not all commercial technologies could be transferred to America’s main strategic enemy, the Soviet Union. The White House was accurately afraid of dual use technologies, namely those that were civilian but could also be used for military purposes. Kissinger limited the sale of high end computers and microchips, for example, only allowing second tier components to be sold to the Soviets.

Although Nixon and Kissinger accurately guessed that US industries would be targets for Soviet espionage, the extent to which the Soviets exploited détente would have been beyond their wildest imaginations. The collection of scientific and technical intelligence from the US was conducted by Soviet military intelligence (GRU) and the KGB, whose operating arm, Line-X, reported to Directorate T (Technology). In 1973 the KGB assigned an officer to New York whose full-time job was to collect (steal) US scientific and technical intelligence (S&T). By 1980 the US was producing more S&T intelligence for Moscow than the rest of the world combined. Visiting Soviet trade delegations to US research centers, laboratories and fortune 500 companies, for example, were packed with undeclared Soviet intelligence officers. In an agricultural delegation of a hundred Soviet officials about one third were known or suspected Soviet intelligence officers. In one visit to a Boeing laboratory a delegate applied adhesive to his shoes to obtain metal samples. The size of the Soviet onslaught was so large that entire fields of US research and development became replicated in the Soviet Union. The East German spy master, Markus Wolf, recalled the East German computer company, Robotron, was, thanks to Soviet espionage, an unofficial subsidiary of IBM.

Soviet S&T espionage was often facilitated by sloppy security at US defense contractors. An employee of TRW Corporations in Redondo Beach, CA, which manufactured a US spy satellite, recalled that workers “regularly partied and boozed it up during working hours with the ‘black vault’ housing the Rhyolite [spy] satellite project”. Bacardi rum, he claimed, was kept behind the cipher machines and a cipher-destruction device was used as a blender to mix banana daiquiris and Mai-Tais.

Soviet espionage was so far reaching that, ironically, by the end of the Cold War both sides of the conflict, NATO and the Soviet Union, were dependent on US S&T.

Business Risk

Fast forward to the present day – a time when the world is vastly more complicated than the last century’s Cold War. Western countries did not need the Soviet economy. By contrast, China is intertwined with the world economy.

Beijing is seeking to portray Washington’s new approach to economic, defense, and foreign policies as undermining the post war rules based international order that it created. Meanwhile the PRC, which, has previously railed against the international order (though in reality it vastly benefited from that order), is holding itself out to be the stable player on the world stage. The PRC’s attitude is that it will play by the rules when it suits it but is happy to break them whenever it decides to do so.

Recent diplomatic outreach to Beijing by Western leaders include agreements framed as pragmatic economic wins. If middle powers, like Britain, for example, pursue a strengthening of commercial relations with China, they will need a strategy to mitigate risk like Nixon and Kissinger developed. Britain does not have a strategy for doing so. Even China hawks, like former US ambassador in Beijing, Nicholas Burns, have stated that for economic growth the US will need to continue to trade with China, but will need to carve out elements of national security and critical infrastructure. The latter is a principle stretching back to the UK government War Book.

There is no reason why the PRC would not seek to exploit a détente with the west as the Soviets did before. The Chinese state and its intelligence services have never encountered a western business whose intellectual property they did not want. The Chinese Communist Party (CCP) uses a constellation of front companies to do business with the outside world. Often such companies will enter into business ventures to obtain intellectual property from their western counterparts, but then pull the plug, bankrupting their western counter parties. To add insult to injury, Chinese firms will often sell the product they have stolen back to western markets.

The name of the game for western businesses must therefore be risk mitigation regarding China. In the last century, governments held the monopoly on the know-how and intelligence critical to the technologies that shaped our world – nuclear weapons. It took state resources to detect technology transfer. Soviet S&T espionage was only discovered when French intelligence recruited an agent in KGB Line-X in the 1980s. The same is not true today. Private sector companies today hold the keys to innovations that will shape our lives this century – microchips, A.I., quantum and bioengineering. It is therefore private sector companies that are best placed to mitigate risk of stolen intellectual property. And unlike in the past, this can be done by using A.I. driven publicly available data.

For much of history, global commerce has operated under a set of stable and predictable assumptions that made both risk and relationships easier to navigate. Standard due diligence—a background check, quick database search, or conversation with a reference—was often enough to understand who you were hiring or who you were doing business with.

The relationships that mattered were visible. The risks that accompanied them were bounded. And the geopolitical environment, for all its turbulence, mostly stayed out of the way of routine commercial decisions.

Today, economic competition runs through a more contested global system—shaped by technological rivalry, supply chain realignment, and tightening constraints on the movement of capital, talent, and information. Organizations are being forced to confront questions they are not fully prepared to answer: Who actually controls the networks we depend on? Where are the exposures we haven’t examined closely enough? How do decisions that seem unrelated accumulate into systemic risk?

The challenge is a surplus of information with no clear way to make sense of it fast enough. The newly enhanced Strider Operating System (OS) was built to change that.

The Vision

“Data is oil. We do the discovery. We put the pipes in the ground. We built the refinery. And now the products go directly into the systems running the enterprise.”

That is how CEO and Co-Founder Greg Levesque describes Strider OS, the company’s new AI-native, agentic intelligence operating system built for this geopolitical era.It ingests billions of publicly available records across dozens of languages, resolves identities, maps relationships, and delivers finished intelligence into client workflows without ever touching client data. At its center is a digital twin of the industrial world, built down to the person level. Your employees, past and present. Your suppliers.  Your corporate relationships traceable through open sources. All in real time, mapped continuously, so organizational leaders can act with clarity and confidence.

Inside the System

Strider OS is not a product you log into. It is a centralized intelligence orchestration layer that sits across Strider’s data, models, and products, powering everything clients use and transforming how organizations access, interpret, and act on strategic intelligence. Clients interact with the intelligence it produces, not the system itself.

In practical terms, it takes raw global data across file types, formats, and dozens of languages and turns it into clean, structured, decision-ready intelligence. The guiding principle is cognitive deload: surface what matters and why it matters, enabling faster and more confident decision-making. Research tasks that previously took weeks of manual work can now be completed with high accuracy in a fraction of the time.

Every insight produced through Strider OS is grounded in validated, original source documentation. The system surfaces facts. It does not accuse, convict, or draw conclusions. Strider’s team of subject-matter experts manage every step of the data processing and analysis.

Three Agents, One Refinery

At the core of Strider OS is an agentic data refinery. Three specialized AI agents each handle a distinct stage of the intelligence production process.

Together, these agents maintain a dataset of over 25 billion objects spanning dozens of languages and countries. Inside that data, the same person can appear under different names, spellings, and affiliations across different sources. The refinery resolves those identities, maps relationships between individuals and organizations, and surfaces signals continuously, at a volume and speed no human team could replicate.

The Human Layer

Strider’s subject-matter experts on PRC, Russian, and Iranian statecraft work directly alongside engineers and data analysts at every stage of the intelligence pipeline. They identify which sources best answer nation-state risk questions. They manage the AI review process. They validate outputs before anything reaches a client.

The AI models Strider uses are internal tools that review source data at scale. One step in a longer process, overseen by analysts who know when something is right and when it falls short. No model is permitted to surface a finding untethered from original source documentation.

Nation-state actors deliberately obscure affiliations, shift tactics, and hide relationships. Catching that requires people who have spent their careers studying them. AI amplifies that capacity—making human judgement even more effective.

What’s New

Deep Research Reports

One of the major enhancements powered by Strider OS is Deep Research Reports: automated, analyst-level intelligence on entities tied to the PRC, Russia, Iran, and the DPRK, delivered in hours, not days. Previously, AI-generated research outputs were long, difficult to validate, and not shaped around the specific question a user needed answered.

Deep Research Reports work differently. Users define their research questions upfront, interact with the system, and provide context to shape the output. What comes back is a structured, narrative report built for executive decision-making, combining risk analysis, market context, and operational insight in one place. Evidence cards and source citations are built in throughout, so any finding can be traced directly back to where it came from.

Earlier Visibility into Geopolitical Risk

Historically, clients received a batch of analyst-built person profiles each month. Coming soon, Strider Insights—powered by Strider OS—will deliver every profile with risk that Strider has available, providing analyst-grade profiles at scale with decision-ready intelligence. These profiles will refresh monthly as new information is collected. With expanded coverage and automated analysis, organizations will gain deeper insight across more people of interest and will be able to actively engage with their full risk landscape.

The Next Frontier

For organizations that want Strider’s intelligence inside the tools they already use, Strider is building toward open integration standards like MCP (Model Context Protocol) that will allow AI models to connect directly to Strider’s strategic intelligence. The underlying data stays the same: validated, source-backed, and governed by the same methodology regardless of where the intelligence is accessed.

The launch of Strider OS establishes the foundation for a new generation of AI-native capabilities and applications, expanding Strider’s ability to support a broad range of economic security use cases across global industry, government, and academia. But the need for it will only grow. The volume of data organizations face shows no sign of slowing, and adversarial nation-states are growing more sophisticated by the day. Legacy systems and human analysis alone cannot close the widening gap between information and understanding. By fusing open-source intelligence with agentic AI to deliver a shared operating picture at the speed this moment demands, Strider OS is defining the next frontier of strategic intelligence.

From the systems that power electrical grids to the communications networks that connect the world, critical infrastructure is the foundation of economic growth and resiliency, national security, public safety, and life as we know it. It is a sprawling web of interdependent systems operating at extraordinary scale—divided by sector, but united by shared technologies, intertwined supply chains, and, increasingly, collective vulnerabilities.

While governments around the world maintain their own definitions of “critical infrastructure,” they largely converge around the same core systems that underpin modern society. Terminology may differ, but critical infrastructure sectors broadly include communications, information technology, and digital infrastructure systems; major energy sources (including electricity, renewables, oil, and gas); financial services and banking; government services and facilities; transportation systems (including air, rail, and maritime); water and wastewater; and defense. These are the sectors that societies rely on—making them uniquely attractive targets.

Adversarial nation-states like the People’s Republic of China (PRC), Russia, and Iran have spent the past decade mapping vulnerabilities in critical infrastructure—learning about them, figuring out how best to exploit them, and infiltrating them. The threat these countries now pose is more coordinated, more persistent, and more strategically targeted than at any prior point in history.

Critical infrastructure systems have become the new terrain through which power is projected and pressure is applied.

The Threat Landscape Has Changed

For organizations in critical infrastructure sectors, reliability has always been a top priority: keeping the power flowing, networks connected, goods moving, and daily life running. That hasn’t changed. But the threat landscape these organizations are operating in has. Today, resilience against adversarial nation-states has become as important as the reliability these systems have always prioritized.

That resilience is already being tested worldwide. Foreign-manufactured components with opaque capabilities have been discovered in Western power grids. Major telecommunications carriers have identified state-linked actors operating within their core networks. Energy and industrial companies in North America and Europe have taken systems offline following attacks that moved through third-party partners and global supply chains. The methods of intrusion are varied, but the scale and coordination point to something more deliberate than opportunistic attacks.

What distinguishes this new landscape is the strategy behind it. Intelligence and law enforcement agencies have assessed with high confidence that recent activity by groups like Volt Typhoon, a PRC state-sponsored hacking group known to target critical infrastructure, is inconsistent with traditional cyber espionage. Meanwhile, Russian-backed groups have targeted power grids, government networks, and financial institutions in Europe, aiming to destabilize and erode public trust. And Iran has gone after critical sectors in both the U.S. and Europe—including healthcare, transportation, and oil and gas—to test vulnerabilities.

These actors are not just trying to steal data. They are pre-positioning themselves deep inside critical systems with the goal of being able to cause disruption on demand. The objective is leverage, and critical infrastructure is how they intend to get it.

Policymakers have taken notice and are taking action. Japan’s Economic Security Promotion Act, enacted in 2022, designated approximately 200 entities across 15 sectors as critical infrastructure operators. The government is enabled to vet equipment suppliers or maintainers to ensure that vulnerabilities aren’t introduced related to foreign entities of concern.

In the United States, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) confirmed that PRC state-sponsored actors had compromised networks across communications, energy, transportation, and water system sectors. Previously, the U.S. banned PRC technology provider Huawei from its 5G and telecommunications networks due to espionage risks.

In its National Security Strategy 2025, the UK government stated that “Hostile activity on British soil from countries like Russia and Iran is increasing, threatening our people, critical national infrastructure and prosperity.” The UK government also pledged to “roll out a series of new measures to…enhance the resilience of our critical national infrastructure.

The European Union, meanwhile, recently moved to restrict PRC suppliers from critical infrastructure, such as telecommunication networks, across member states entirely.

These actions make clear that critical infrastructure is a prime target for adversaries. For those responsible for keeping these systems safe and secure, understanding where and how deeply they have already been reached—and the strategies being employed by adversarial nation-states—has become essential for safeguarding economies and societies.

Where Critical Infrastructure Is Most Exposed

Understanding where adversaries are finding their way in starts with understanding how exposure accumulates—and it rarely happens the way most organizations expect. It comes through procurement decisions made without full visibility, hires that passed every background check, and partnerships that looked clean on paper. For organizations across critical infrastructure sectors, the risk concentrates in three places.

The first is the supply chain. The global supply chain for critical infrastructure components is vast, layered, and can often be difficult to trace. While that complexity is a byproduct of operating at global scale and within intertwined economies, it is also one of the most consequential vulnerabilities that organizations face. Adversaries have spent years learning to exploit it. The result has been solar inverters with undisclosed communication capabilities; telecommunications hardware sourced from entities with government ties; and transformers, fiber optic cables, and industrial control components whose origins cannot be verified.

Strider’s “In Broad Daylight” report captured exactly what that exploitation looks like in practice. In November 2024, PRC-linked company Deye remotely disabled inverters across the United States, United Kingdom, and Puerto Rico following a commercial dispute. The capability had been embedded in the hardware before it ever reached the grid. The leverage was already in place. The dispute simply revealed it. Strider research also shed light on the sustained PRC effort to identify vulnerabilities and develop methods to disrupt Western power grids—uncovering 2,723 publications on the subject authored by researchers affiliated with PRC defense institutions, including the People’s Liberation Army and national defense universities.

The second is the workforce. Privileged access to critical infrastructure systems is among the most valuable things an adversary can acquire—and state-sponsored actors are pursuing it methodically through recruitment, cultivation, and talent pipelines that look entirely legitimate from the outside. In 2023, that reality came into sharp focus when a telecom contractor in Florida was charged with acting as an agent of China’s Ministry of State Security while maintaining active system access at a major U.S. carrier. For every case like this that surfaces, the harder question is how many have not. Any organization that relies solely on conventional vetting methods is likely carrying risk that has not yet been illuminated.

The third is the extended partner ecosystem. Every joint venture, contractor relationship, and operational partnership is a potential entry point for adversaries to exploit. Partners bring their own supply chains, personnel, and geopolitical entanglements into shared operational environments, and there is rarely visibility into the full ecosystem. In the oil and gas sectors, where global operations and joint ventures are common, adversaries actively seek out partnerships as digital access points to disrupt operations and gain strategic advantage. Intellectual property from exploration breakthroughs, refining processes, and material-science research are frequent targets—compromised through the same trusted partnerships that companies depend on to operate. When any part of that ecosystem is compromised, the entire organization is compromised with it.

A Strider Use Case: A Major Energy Provider Prevented Exposure

A prominent U.S. power and energy company servicing some of the largest metropolitan areas in the country wanted to ensure its critical systems were safeguarded from nation-state threats. Company leaders wanted full visibility into the entities within its ecosystem as third-party partners or technology providers.

The company used Strider’s strategic intelligence platform to identify all entities with technology embedded in its infrastructure, then screened every third-party partner involved in day-to-day operations for connections to foreign entities of concern. What they found was alarming. A substantial portion of their critical infrastructure was being managed by a third-party company with direct connections to the PRC government, military, and defense organizations. The relationship posed a serious risk: this energy company could potentially lose operational control of their critical systems to a PRC government entity or actors working on its behalf. Company leaders severed ties with the management company.

For organizations involved in critical infrastructure sectors, this case illustrates something important: the exposure existed before anyone went looking for it. It only became visible when they had the right tools to see it.

How Strider Helps Critical Infrastructure Organizations

The organizations that manage risk posed by adversarial nation-states best are the ones that can see it clearly across their supply chains, their workforce, and their extended partner ecosystem. Most organizations have invested heavily in tools designed to detect threats after they’ve entered their critical systems. Strider’s strategic intelligence enables organizations to get ahead of these threats.

For supply chain and partner risk, Organizations Search maps the full ownership and affiliation picture behind every vendor, supplier, component, joint venture partner, and major contractor embedded in an operational environment—uncovering multi-tier relationships, hidden parent companies, and state-linked intermediaries.

For workforce risk, People Search screens employees, contractors, and candidates for nation-state ties, falsified credentials, and risky affiliations—revealing hidden connections that conventional background checks were never built to detect.

Across all three, Insights tracks the specific technologies and subject-matter experts most likely to be targeted by state actors and generates reporting for leadership on emerging geopolitical and partner risks.

And Shield flags and blocks malicious domains, emails, and communications tied to known adversary campaigns—feeding high-risk indicators into existing security systems to monitor risky inbound and outbound activity before it reaches operational environments.

Strider also provides expert analysis within its Intelligence Center on critical infrastructure security—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.

The systems that make up critical infrastructure are only as resilient as the technologies, supply chains, and people that support them. Strider gives organizations the visibility to understand that full picture and to act on it before someone else does.

Conclusion

Critical infrastructure is the foundation that modern society cannot function without. And precisely because of that, it has become a primary target for those seeking leverage in this new geopolitical era. Keeping it secure, reliable, and free from foreign interference requires a level of vigilance that many organizations have not yet applied—but must.

Those who act now will find the exposure. Those who wait will feel it.

Russia launched its full-scale invasion of Ukraine on February 24, 2022, initiating one of the largest conflicts in Europe since World War II. This war, which has lasted far longer than many experts anticipated, has led to widespread international condemnation and a significant humanitarian crisis.

Over the past three years, Russia’s technology sector has fallen behind, and the Kremlin is now resorting to increasingly nefarious tactics to close the gap and achieve “technological sovereignty”—its ability to develop, control, and maintain its own critical technologies and technological infrastructure without relying on foreign countries or multinational corporations. 

This concept has gained increasing importance for Russia, especially in the context of geopolitical tensions, economic sanctions, and its efforts to insulate its economy and national security from external influence.

In this article, we’ll talk about the drivers behind Russia’s technological stagnation, four areas where they’re adapting their tactics, and the steps your organization can take to protect your own technology. 

For a deeper dive, though, download “Navigating the New Geopolitical Reality”—a comprehensive white paper written by Strider’s Global Intelligence Unit about Russia’s evolving strategy.

Russia adapts economic espionage tactics in Europe

Its ongoing war with Ukraine has been devastating to Russia’s technology sector, which continues to lag further behind the West.

As a result, Russia is adapting its strategies to navigate economic isolation and sustain its technological edge. This includes a growing reliance on individuals operating under non-official cover—such as oil and gas workers, professors, and other professionals—who may utilize social media platforms like LinkedIn to connect with targets in Europe and the United States.

This means that private companies are now being subjected to greater risk from Russia and other adversarial nations.

The Kremlin ramps up reverse-engineering efforts

After Russia invaded Ukraine, many firms chose to close up shop in Russia and move elsewhere. Likely as a form of retribution against those firms, Russian president Vladimir Putin directed the government to use funds from the “exit tax” imposed on foreign companies leaving Russia to finance reverse-engineering initiatives.

As a result, since 2022, the Russian government has funneled at least $110 million USD into projects focused on imitating Western-made products. This push toward imitation technology has raised concerns that foreign companies may face increased competition from Russian knockoffs in markets favorable to Russia, such as India. 

The Russian government is seeking to reverse engineer hundreds of products manufactured by leading American and European companies, including integrated circuits, chemical compounds, automotive parts, and engines, and weapons systems.

Russia leverages relationships for “gray zone” operations

“Gray zone” activities—such as arson, attempted bombings, vandalism, cyberattacks, propaganda and misinformation, territorial encroachment, and other disruptive actions—generally fall between traditional states of peace and war. These actions, in which Russia has been heavily involved, are often ambiguous, covert, or non-traditional, designed to achieve strategic objectives without crossing thresholds that would typically provoke a formal military response or war.

The Russian government has reportedly been analyzing online profiles of individuals in Europe to identify those who may be susceptible to manipulation by the Kremlin—and then using them to target infrastructure and organizations (especially those providing support to Ukraine) as part of a broader campaign intended to create chaos and undermine NATO and EU cohesion. 

The European Union has increased export prohibitions in an attempt to punish Russia for evading sanctions 

Starting in January 2025, new prohibitions on exports to Russia will raise compliance burdens and risks for businesses based in the European Union (EU).

Since the war started in 2022, the EU and its allies have implemented hundreds of sanctions aimed at limiting Moscow’s access to foreign technology necessary to sustain the war. These sanctions, however, are notoriously difficult to uphold, and third-party countries continue to play a key role in helping Russia evade them. According to Ukraine’s military intelligence agency, there has been no significant change in the flow of foreign components to Russia.

Read more about how companies with ties to Russia—including some within Ukraine—pose a risk to Western organizations.

What can you do to mitigate risk for your organization?

This complex environment requires more than traditional due diligence or surface-level risk assessments. Organizations must have a comprehensive understanding of how state actors—like Russia—manipulate supply chains, leverage global networks, and exploit access to sensitive technology.

Strider’s Organizations Search provides unparalleled visibility into complex supply chains, uncovering hidden connections to state-sponsored actors and high-risk entities. This is especially critical in the context of Russia’s evolving tactics to acquire foreign technology despite extensive sanctions.

Russia’s strategies for sustaining its technological edge and navigating economic isolation have drastically shifted in recent years, particularly since the war in Ukraine.  

During our recent webinar, Navigating the New Geopolitical Reality, Strider intelligence specialists delved into the findings from our latest white paper and shared actionable insights for organizations to safeguard their operations.  

If you missed it, here are five key themes we explored. 

1. Technological Sovereignty: Russia’s Driving Ambition 

One of the central themes discussed was Russia’s pursuit of “technological sovereignty.” This concept underscores Russia’s effort to reduce its reliance on foreign technologies and talent, a challenge exacerbated by sanctions, export controls, and a significant brain drain. 

To achieve these goals, Russia has intensified efforts to recruit foreign talent, leverage academic connections, and invest in domestic reverse engineering projects. As a Strider intelligence specialist highlighted, “Russia’s push for technological sovereignty isn’t just about survival—it’s a long-term strategy to dominate key industries.” 

2. Reverse Engineering as a Strategic Pillar 

Reverse engineering emerged as a critical focus area in the discussion. Russia has been using funds from its “exit tax” on departing foreign companies to finance reverse engineering projects aimed at replicating Western technologies. These efforts, often coordinated with intelligence agencies, target industries like defense and high-tech manufacturing. 

A Strider expert noted, “The integration of intelligence services into reverse engineering projects allows Russia to weaponize this knowledge, not just for domestic use but also to compete in global markets. The partnership between Russia and Iran further amplifies the risks.” 

3. The Shift in Espionage Tactics 

Sanctions and diplomatic restrictions have disrupted Russia’s traditional intelligence networks, leading to a reliance on unconventional methods. Strider intelligence specialists explained that Russia increasingly recruits individuals already living in Europe and leverages online platforms like LinkedIn to target potential assets. This shift toward “non-official covers” has made it harder for organizations to detect and mitigate risks. 

The team emphasized that “Strider’s intelligence solutions are uniquely positioned to uncover these connections, flagging risk signals tied to individuals and entities with potential ties to state-sponsored activities.” 

4. Gray Zone Operations: Beyond Espionage 

The webinar also explored Russia’s “gray zone operations,” which encompass sabotage, vandalism, and cyberattacks targeting countries and organizations supporting Ukraine. These low-cost, high-impact tactics aim to sow fear and undermine cohesion within NATO and the EU. 

A Strider expert highlighted, “Russia’s gray zone tactics blur the lines between traditional and unconventional warfare, making it essential for organizations to stay vigilant and proactive.” 

5. Sanctions Evasion: A Persistent Challenge 

The discussion wrapped up with insights into Russia’s sophisticated sanctions evasion networks. Despite stringent export controls, Russia continues to acquire critical technologies through intermediaries in countries like China and Turkey. The upcoming EU enforcement of “No Re-Exports to Russia” clauses in 2025 was highlighted as a key development to watch. 

A Strider specialist observed, “Sanctions are like a game of whack-a-mole—just as one network is disrupted, another emerges. The private sector plays a critical role in staying ahead by conducting rigorous supply chain due diligence.” 

How Strider Can Help 

The webinar underscored the importance of leveraging strategic intelligence to mitigate risks posed by state-sponsored actors. Strider’s platform combines advanced analytics with exclusive data to provide unparalleled visibility into supply chain vulnerabilities, personnel connections, and other risk factors. 

As a Strider intelligence specialist put it, “Every organization has unique challenges, and Strider is here to help you tackle them at scale.” 

Next Steps 

For a deeper dive into these insights, we encourage you to: 

If you’d like to discuss how these themes specifically impact your organization, schedule a consultation here.  

Together, we can navigate these challenges and protect what matters most. 

This is the third post of four in our Research Security blog series. To read the previous post, click here.

Introduction  

In an interconnected world, the security of research activities has far-reaching implications. The lack of robust research security measures can lead to significant global repercussions, affecting everything from national security to economic stability. This blog explores the global effects of inadequate research security, particularly focusing on the actions of the PRC and Russia, and highlights the importance for academic institutions to maintain compliance to secure and protect funding. 

Scope of the Challenge  

Research security breaches are not isolated incidents; they are part of a broader strategy by certain state actors to gain competitive advantages. The PRC and Russia, in particular, have developed sophisticated methods to exploit vulnerabilities in the global research ecosystem. 

Examples of Breaches and Their Consequences 

  1. Intellectual Property Theft: The theft of proprietary research and technology can cripple innovation in affected countries. For example, Chinese entities have been implicated in numerous cases of IP theft, leading to significant economic losses and stifling competitive advantages. 
  1. Unapproved Technology Transfer: Collaborative research without adequate security can result in sensitive technologies being transferred to hostile entities. This has implications for national security, as advanced technologies can be used to enhance military capabilities in adversarial nations. 
  1. Talent Drain: High-profile talent recruitment programs by the PRC have lured top researchers away from their home institutions, leading to a brain drain that undermines domestic research capabilities and innovation potential. 

Case Studies 

Understanding and Mitigating Risks 

Effectively mitigating risks is crucial for protecting intellectual property and maintaining research collaboration integrity. Institutions must comply with regulations from entities such as the Department of Defense (DOD), Department of Energy (DOE), and National Science Foundation (NSF) to secure and maintain funding. This requires thorough vetting of research partners and donors to avoid high-risk affiliations, ensuring transparency in all research activities and partnerships to meet regulatory requirements and prevent penalties, and safeguarding intellectual property while maintaining a research environment free from undue surveillance concerns. 

Leveraging Advanced Intelligence Tools 

Leveraging advanced data processing and risk analysis capabilities, institutions can identify high-risk collaborations and implement measures to safeguard their research, personnel, and funding. By ensuring compliance and protecting research activities, institutions can protect funding and maintain a competitive edge.  

Strider’s comprehensive data analysis and risk intelligence capabilities enable institutions to identify and mitigate these risks effectively. By providing visibility into potential threats and offering strategic insights, Strider helps safeguard research integrity and innovation. 

Conclusion  

The global effects of inadequate research security are profound and multifaceted. To protect funding, intellectual property, national security, and innovation potential, it is imperative to implement robust research security measures. Strider stands at the forefront of providing the tools and insights necessary to navigate these challenges. 

This is the third post of four in our Research Security blog series. To read the next post, click here.

This is the second post of four in our Research Security blog series. To read the first post, click here.

Introduction  

In the realm of international research, collaboration is often seen as a pathway to innovation and progress. However, not all collaborations are benign. The People’s Republic of China (PRC) and Russia have strategic motivations for encouraging open-source research collaborations that go beyond academic advancement. Understanding these motivations is crucial for safeguarding intellectual property, maintaining research integrity, and ensuring compliance with funding regulations. 

The PRC’s Strategy  

China’s ruling party takes direct control of the country’s universities, with presidents’ offices being merged with embedded party committees to form a ‘unified’ leadership for higher education. This centralized control is part of a broader strategy to advance national objectives through scientific and technological development. 

Xi Jinping, General Secretary of the Communist Party of China, has explicitly called for the PRC to achieve “high-level science and technology (S&T) self-reliance.” This directive is reflected in the party’s emphasis on “indigenous innovation,” which aims to reduce dependence on foreign technology and bolster China’s global competitiveness. 

Tactics Employed  

The PRC employs several tactics to exploit international collaborations: 

Case Study: University Involvement  

An example of this strategy is seen in China’s emphasis on brain research through the China Brain Project, which involves substantial government funding aimed at attracting global talent and expertise. International collaborations in such projects are closely monitored and leveraged to advance China’s strategic goals. 

Russia’s Approach  

Since 2022, the Russian government has poured significant resources, at least USD 110 million, into initiatives aimed at reverse engineering Western goods, particularly to copy Western weapon systems. Universities are integral to these efforts, offering training and conducting projects designed to replicate and improve upon Western technologies. At least two of the universities leading these projects have been involved in economic espionage activities, demonstrating the extent to which academic institutions are leveraged for state objectives (DNI.gov) (ProPublica). 

Implications for Global Research  

The strategic motivations behind the PRC and Russia’s calls for open-source research collaboration pose significant risks to international research institutes. These include: 

Ensuring Compliance and Protecting Funding  

For many academic institutions, the primary concern is compliance with regulations from bodies such as the Department of Defense (DOD), Department of Energy (DOE), and National Science Foundation (NSF) to secure and maintain funding. This involves: 

Mitigating Risks Through Advanced Intelligence 

Understanding and mitigating these risks is essential for protecting intellectual property and maintaining the integrity of research collaborations. Leveraging advanced data processing and risk analysis capabilities, institutions can identify high-risk collaborations and implement measures to safeguard their research and personnel. This approach helps secure funding while ensuring compliance with necessary regulations.  

The recent memorandum from the Office of Science and Technology Policy (OSTP) further underscores the importance of robust research security programs. It provides guidelines for federal research agencies to implement certification requirements for research security programs at covered institutions, aligning with National Security Presidential Memorandum-33 (NSPM-33) and the CHIPS and Science Act. These guidelines emphasize the need for cybersecurity, foreign travel security, research security training, and export control training. 

Specific Tools for Risk Mitigation 

Strider provides unique intelligence and tools necessary to identify and mitigate these risks. By leveraging our advanced data processing and risk analysis capabilities, research institutions can protect their intellectual property and maintain the integrity of their collaborations. Specifically: 

Conclusion  

While international collaboration is essential for scientific progress, it is crucial to remain vigilant about the hidden motivations of certain state actors. Understanding and addressing these risks ensure that research efforts contribute positively to global innovation and security. By staying informed and proactive, research institutions can continue to collaborate safely and advance their mission of expanding knowledge and creating a better world without compromising compliance or funding. 

This is the second post of four in our Research Security blog series. To read the next post, click here.

Competing Governments and Global Economic Risks 

Today, many governments are using their international economic relationships to achieve their own strategic goals. Sometimes, this comes at the expense of their global partners. Countries like the PRC, Russia, and Iran often put this strategy to use to further their own technological interests, making it harder for businesses and academic institutions worldwide to protect themselves from these risks. 

That’s why Strider created Organizations Search, our third-party due diligence tool for security, compliance, and reputational insights. 

Huge Organizations Search Data Expansion 

This month, we’re excited to announce some major improvements to Organizations Search. These new milestones significantly contribute to our vision of Organizations Search being a comprehensive risk screening solution for strategic state-sponsored intervention in the global economy.  

Most notably, Organizations Search now includes government registration records for 200 million legal entities located in the United States, Canada, Europe, and Japan. Integration of this data into Organizations Search reflects the rapid maturation of Strider’s ability to illuminate risky economic connections around the world, not just within regions of special concern. 

In the coming year, we’ll be adding even more data sources related to cross-border trade, ownership, and other economic relationships. With these updates, our clients will gain an even deeper understanding of which organizations might pose a risk due to their economic connections. After all, state-sponsored actors don’t limit themselves to their home countries—they own, trade with, and collaborate with millions of organizations around the world. Our clients know this and are looking for scalable solutions to manage these risks. 

New Data from Russia and Iran 

We’re also excited to announce two new data additions specifically focused on Russia and Iran.  

First, we’ve added over 5 million supplier relationships from Russian government procurement records. This data shows which commercial firms in Russia have contracts with military, defense, and government end users. Understanding these connections can help our users identify companies with economic incentives to align with Russian government priorities. 

Second, we’ve added 2 million legal entities from Iran’s business registration system. This will help our users gain more insights into businesses operating in that often opaque region. 

Looking Ahead 

In today’s unpredictable globalized business environment, this type of comprehensive due diligence is more critical than ever before. 

These updates are just the beginning. We have many more exciting data expansions and features planned for Organizations Search in the coming months. These enhancements will further empower our users to screen broadly and deeply for state-sponsored risks within their global economic footprints.  

Learn more about Organizations Search here.

Request a demo to see what insights Organizations Search can unlock for your organization.

Executive Summary

Understanding the Complex Landscape of Ukrainian Businesses with Ties to Russia 

In the shadow of the ongoing conflict, Ukrainian businesses with ties to the Russian defense industry present a thorny challenge for investors and organizations committed to aiding Ukraine’s reconstruction.  

The Depth of Russian Influence 

The scale of Russian influence in the Ukrainian corporate sector is alarming. Following the invasion, it was reported that Russian and Belarusian individuals owned over 20,000 companies in Ukraine.  

In response, the Ukrainian government has taken legislative steps aimed at severing these ties, including laws enabling the seizure of Russian properties in Ukraine. Some businesses linked to notorious Russian oligarchs have already been confiscated. However, the process has been anything but smooth. Bureaucratic hurdles and a shortage of staff at the Ministry of Justice, the body responsible for proving commercial links to the Russian state and its citizens, have significantly hampered these efforts. 

As of August 2023, a startlingly low figure of approximately 5% of these entities had seen a change in ownership. This slow pace of divestment points to a persistent economic influence that Russia holds in Ukraine, complicating efforts to disentangle the two economies. 

The Rebuilding Effort and Associated Risks 

The World Bank’s estimation that rebuilding Ukraine will cost around $400 billion underscores the magnitude of the task ahead. Yet, as Ukraine looks to take on this monumental effort, the lingering connections of many Ukrainian businesses to Russia and, specifically, its defense industry, represent a minefield of risks.  

Notably, some of these businesses with Russian defense ties continue to be awarded government contracts, raising questions about the efficacy of the measures taken to free the Ukrainian economy of Russian influence. 

The Implications for Investors and Aid Organizations 

The intricate web of Ukrainian businesses tied to Russian interests poses significant hurdles for the international efforts aimed at rebuilding Ukraine. Investors and organizations eager to participate in this monumental task must navigate a landscape riddled with both legal complexities and reputational perils. The revelation that a significant number of these entities remain entwined with Russia, including its defense sector, underscores the urgency of addressing these challenges head-on. 

To safeguard the integrity and effectiveness of the rebuilding efforts, it is imperative for stakeholders to implement rigorous due diligence processes. Understanding the ownership structures and financial flows of potential Ukrainian business partners is crucial to avoid inadvertently supporting those with links to Russian aggression. 

As Ukraine strives towards recovery and sovereignty, the path forward demands not only physical reconstruction but also a steadfast commitment to economic independence and transparency. By tackling the complexities of Russian-linked ownership, the global community can contribute to a foundation for Ukraine that is not only rebuilt but also resilient against future threats.