MAGI
Eric O’Neill
Published on July 22, 2026 · 10 min read

Contents
What is the Kremlin’s criminal army?
How do cybercriminals become state proxies?
Why does plausible deniability matter?
How should organizations respond?
What does this mean for identity and trust?
What practical lessons should readers remember?
The Kremlin’s criminal army is the article’s name for a simple idea: modern intelligence services no longer need to build every capability themselves. In today’s Russian cyber ecosystem, criminal groups can function as digital cutouts, giving states reach, access, and deniability through activity that often looks like ordinary cybercrime.
This guide stays faithful to that core arc. It follows the source article through Cold War tradecraft, Russia’s cyber ecosystem, the attempted disruption of Poland’s energy grid, the role of credential theft and ransomware, and the larger warning that trust itself has become a prime target.
Start with the definition, then follow the pattern. Once you see how cyber proxies work, the rest of the story becomes much harder to ignore.
What is the Kremlin’s criminal army?
The article’s central claim is that modern intelligence services have turned cybercriminal groups into digital-era cutouts.
During the Cold War, intelligence officers relied on intermediaries known as cutouts. Those trusted go-betweens delivered money, passed messages, arranged secret meetings, and insulated the intelligence officer from discovery. The same tradecraft now operates through ransomware gangs, malware developers, credential thieves, hosting providers, and other technical enablers.
The Kremlin’s criminal army is the modern cyber ecosystem in which state objectives are advanced through criminal proxies, technical enablers, and deniable digital operations. This convergence turns ordinary-looking cybercrime into an instrument of national power.
Why cybercriminals make effective spies
Governments use cybercriminals because criminal groups already offer access, infrastructure, and plausible deniability. The brilliance of the cutout was never convenience. It was insulation from exposure.
A government no longer has to recruit and train every hacker from scratch. Criminal organizations already possess malware, ransomware, credential theft, cryptocurrency laundering, and hosting infrastructure. To the victim, the operation can look like routine cybercrime. To an intelligence service, it becomes another instrument of national power.
How to do it right
That is the insider lesson running through the article. The smartest operations hide behind someone else’s fingerprints, and in cyberspace those fingerprints increasingly belong to criminals.
Spy Hunter’s Lesson: The best intelligence operations hide behind someone else’s fingerprints. In cyberspace, those fingerprints increasingly belong to criminals.
Quick tip: Before moving on, stop treating credential theft as a routine IT problem and start asking who else benefits from the access. Once stolen credentials become intelligence assets, the incident is no longer just about crime.
How this cyber ecosystem works
The article describes a recognizable pattern, not a single hack. Once you understand the sequence, the relationship between cyber proxies, digital espionage, and state power becomes much clearer.
We’ll cover four key phases:
- Phase 1: Criminal capability already exists
- Phase 2: State interests align with that capability
- Phase 3: Access is reused for espionage or sabotage
- Phase 4: Exposure still leaves room for denial
Let’s walk through each one.
Keep reading with Eric
From criminal access to geopolitical leverage
Before any state benefit appears, the criminal market has already built the tools, access, and infrastructure. That is what makes this system so effective. Governments can step into an ecosystem that is already active, already profitable, and already difficult to untangle.
Here’s what that looks like in practice:
- Criminal operators steal credentials, run malware, or deploy ransomware because those activities already pay.
- Governments can exploit that access when it overlaps with strategic targets such as public services, elections, or critical infrastructure.
- Once the operation is exposed, officials can dismiss it as independent hacking while still benefiting from the foothold.
Why the line is so hard to see
The cover story works because it is borrowed, not invented. A criminal motive can be completely real, which makes the espionage layer harder to spot. The operation does not need a fake backstory when the visible crime already provides one.
Victims often experience a familiar cybercrime pattern first, not an obvious intelligence operation. **Access obtained for profit today may be repurposed for espionage or sabotage tomorrow.**
What the victim experiences
From the victim’s side, the first signs may look ordinary: a stolen password, a ransomware demand, a compromised contractor account, or a suspicious login. That surface-level familiarity is part of what makes digital cutouts so useful.
The deeper problem is that the visible crime may not be the full objective. The ransom, the theft, or the disruption can be the most obvious piece of the story while the more strategic value sits behind it.
The question most people skip
The habit Eric pushes is simple: do not stop at the first explanation. Ask what else the access makes possible and who else might benefit from it.
Here’s the framework we recommend:
- Who committed the visible crime?
- Who benefits from the access behind it?
- What strategic objective might matter more than the ransom?
What the sanctions reveal
The UK and EU sanctions revealed what officials described as a broad Russian cyber ecosystem tied to espionage, sabotage, ransomware, credential theft, and attacks on critical infrastructure.That is the direct answer to what the sanctions showed.
Most headlines focused on the sanctions themselves. The deeper story is what the article emphasizes: modern states can outsource digital power to criminal proxies instead of building every cyber capability in-house.
2.2 A sub-header – a part of the category
The ecosystem blends state services, criminal proxies, and technical enablers.
Key points from the announcements:
- The ecosystem blends state services, criminal proxies, and technical enablers.
- Targets include credential theft, malware development, ransomware activity, and attacks on public services.
- The point is not only profit. It is power, reach, and deniability.
A real example: the Poland energy-grid attempt
British officials said a Russian-attributed cyberattack attempted to disrupt Poland’s energy grid.
The attack failed, but the warning is the point. Cybercrime becomes much more dangerous when it serves strategic state goals rather than cash alone.
The Kremlin’s criminal army at a glance
Here is a quick comparison between visible forms of cyber activity and the hidden strategic value behind them.
| Feature | Credential theft | Ransomware | Critical infrastructure disruption |
|---|---|---|---|
| Visible motive | Stolen access and resale | Payment demand | Operational disruption |
| Hidden state value | Persistent intelligence access | Cover for broader intrusion | Coercion and geopolitical pressure |
| Why it matters | Trusted logins become intelligence assets | Crime can distract from espionage goals | Civilian systems become leverage points |
| Best question to ask | Who else can use this account? | Who benefits beyond the ransom? | What strategic message does this send? |
There is no clean line between cybercrime and espionage once the same access can serve both.
Why identity is now the battlefield
Forgotten administrator accounts, stale VPN credentials, dormant contractor logins, and privileged service accounts are not minor leftovers. They are opportunities. That is why identity has become the battlefield.
Frequently asked questions
What makes cybercrime useful to intelligence services?
Because criminal groups already provide access, infrastructure, and deniability, which lets states benefit without openly owning the operation.
Is ransomware always just about money?
No. The article’s point is that a ransom demand may also distract from broader espionage goals.
Why do stolen credentials matter so much?
Because trusted accounts can become intelligence assets, especially when they belong to administrators, contractors, or service accounts.
What should organizations do first?
Audit dormant accounts, review privileged access, and stop treating identity risk as a minor housekeeping issue.
Getting started with this lesson
Understanding deception matters only if it changes behavior. The practical lesson in this article is not to panic. It is to start looking at trust, identity, and access the way an adversary would.
Here’s your action plan for the next 7 days:
- Day 1-2: Review dormant employee, contractor, and service accounts.
- Day 3-4: Check where privileged access lacks phishing-resistant multi-factor authentication.
- Day 5-6: Revisit incident response assumptions and ask where ordinary crime could mask espionage.
- Day 7: Share the lesson with leadership: the real target is often trust.
Do not try to overhaul everything at once. Start with one trust weakness and close it. Security is not only about stronger defenses. It is also about removing the forgotten keys under the welcome mat.
Key Takeaways
- The Kremlin’s criminal army is a cyber ecosystem where criminal activity can serve state objectives.
- Plausible deniability is the strategic advantage that makes digital cutouts powerful.
- Access stolen for profit today can be reused for espionage or sabotage tomorrow.
- Identity, trust, and forgotten accounts are practical security priorities, not side issues.
- The smartest question after any cybercrime story is still: who else benefits?
The better you understand how deception works, the more difficult you become to deceive.
Eric O’Neill
Subscribe to Spies, Lies & Cybercrime
If this story sharpened how you think about espionage, cybercrime, and the hidden game behind familiar headlines, subscribe for the next issue here.
https://spies-lies-cybercrime.ericoneill.net/
MAGI
Blog · Resources · Contact
© 2024 Magi. All rights reserved.
How modern intelligence services turned cybercriminals into the world’s most effective spies. This is the story of how governments use criminals as digital cutouts, why the Russian cyber ecosystem matters, and why cybercriminals as spies have made trust the most valuable target in the system.