The lines between cybercrime and espionage are increasingly blurring, eroding the traditional distinctions between criminal hackers and state-sponsored actors.Following the invasion of Ukraine, TA829 began conducting targeted espionage campaigns in Ukraine, in alignment with Russian state interests, in addition to its more traditional cyber extortion campaigns. TA829’s typical techniques, tactics and procedures (TTPs) involve phishing campaigns to deploy variants of its SingleCamper (aka SnipBot) an updated version of the RomCom backdoor or the lightweight DustyHammock malware.The group’s automated and scaled processes, such as the regular updating of packers and loaders, the use of varied sending infrastructure and source addresses for each target and the use of extensive redirection chains to detect and evade researchers, are more typical of cybercriminals compared to espionage.TA829’s activity has been relatively quiet over the past year until the group resurfaced in February 2025 with a series of campaigns aimed at deploying a previously unobserved malware payload. Is government espsionage among its citizens a cybercrime ?

