Google

Luke Jenkins

Luke Jenkins

2026

From the Battlefield to Your Phone: The Evolution of UNC5792’s Operations

A new, highly adaptive component of the Russian Security Services (FSB) emerged with targeted campaigns against Ukrainian Signal and WhatsApp users across government and military sectors. Throughout 2026, this threat actor—tracked as UNC5792—has aggressively expanded its operations, executing mass-scale Signal account takeovers targeting high-ranking government officials, military leaders outside of Ukraine, and non-governmental organizations (NGOs).

This talk unravels the lesser-known, hybrid mechanics of UNC5792 campaigns as they bridge the gap between remote cyber operations and tactical, physical proximity. We will trace their operational lifecycle: from harvesting intelligence from mobile devices seized on the battlefield, to compromising mobile messaging applications, orchestrating sophisticated credential-phishing campaigns, and deploying bespoke mobile spyware via close-access operations. Attendees will walk away with an in-depth threat profile of UNC5792's evolving toolkit and practical strategies to defend high-value mobile targets against hybrid espionage threats.

 


About Luke Jenkins

Luke Jenkins is the Technical Lead of the Russia and Eastern Europe (RUEE) mission at Google Threat Intelligence Group (GTIG). He has been at the forefront of geopolitical cyber conflict since early 2022, focusing his efforts on tracking, analyzing, and neutralizing Russian-backed threat actors and APTs. Luke previously served as a Technical Manager running the Russia team, building on his foundational experience as a Technical Principal Analyst on Mandiant’s Cyber Espionage team.