The Russian hurdle in Trump’s new offensive cyber program

U.S. President Donald Trump (R) and Russian President Vladimir Putin arrive for a press conference at Joint Base Elmendorf-Richardson on August 15, 2025 in Anchorage, Alaska.

U.S. President Donald Trump (R) and Russian President Vladimir Putin arrive for a press conference at Joint Base Elmendorf-Richardson on August 15, 2025 in Anchorage, Alaska. Andrew Harnik/Getty Images

The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.

President Donald Trump’s new plan to enlist private companies to help disrupt cybercriminals abroad may face a fundamental problem when it comes to Russia: distinguishing criminal hackers and state-backed operatives.

Russian intelligence services have long tolerated, protected or intermittently recruited financially-motivated hackers without exercising full control over them. That dynamic gives Moscow easier access to hacking talent, and it complicates a major carveout in Trump’s new directive that excludes groups part of or directed by a foreign government, experts and former U.S. officials say.

“The line between government control, government-affiliated and government-acknowledged is certainly blurry in Russia,” said Michael Daniel, president and CEO of the Cyber Threat Alliance and a former White House cybersecurity coordinator under President Barack Obama. “Determining the exact relationship between malicious actors and the Russian government has long been a challenge and is often impossible.”

A White House memorandum signed last week paves the way for vetted U.S. companies to conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups. Companies would work under contracts with the Justice Department and Department of Homeland Security, and every operation would require written approval.

The memo says eligible targets cannot be “an institutional part of a foreign government” or “wholly operated under a foreign government’s direction.” It then instructs officials to assume a group is not part of, or wholly controlled by, a foreign government unless “clear intelligence” establishes that connection.

Such intelligence collection from spy agencies like the National Security Agency and CIA can help firms determine targeting criteria, though it may not be enough for Russia’s ever-evolving cyber landscape.

“Russia’s cyber web is opaque and always shifting, blurring lines between government and cybercriminal, with no single rule for understanding each and every relationship,” said Justin Sherman, CEO of Global Cyber Strategies, a Washington, D.C.-based research and advisory firm.

Some of that ambiguity is intentional and allows the Kremlin to expand the pool of hackers it can covertly draw upon, Sherman said. It also reflects broader and pervasive corruption conditions inside Russia.

U.S. companies may have insights about those groups but lack the broader intelligence available to the government. Federal agencies, meanwhile, can only share or declassify so much, he said. “Private companies have critical insights in some ways and limited in others,” Sherman said. With an incomplete picture, “you’re bound to get it wrong some of the time.”

Simple indicators don’t necessarily settle attribution questions, he added. Ties with the FSB — Russia’s Federal Security Service that succeeded the Soviet Union’s KGB — do not by themselves prove that a criminal group is state-directed, nor does a Russian intelligence service’s use of tools developed by criminals establish continuous government control.

“Simple, bumper sticker ideas for deciding if a Russian cybercriminal is a state actor or not will often collapse in practice,” said Sherman.

Past cases illustrate how those relationships can work. In 2017, the DOJ charged two FSB officers with directing and protecting criminal hackers involved in the breach of Yahoo. Prosecutors said one of the hackers also conducted separate intrusions for personal profit. The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, worked for the FSB and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.

“The Russians haven’t been strangers to using private sector proxies to get what they want, as long as they’re not attacking them,” said Chris Painter, a former State Department cyber coordinator and White House cyber official. He questioned how a company could determine where a particular group falls along that continuum when the answer is often not immediately apparent, even for well-resourced governments.

The new policy is the latest step in an offensive cyber posture the administration has been building for the last year. Trump’s national cybersecurity strategy, released in March, called for “unprecedented coordination” between government and industry on offensive and defensive missions. It pledged to “unleash the private sector” by creating incentives for companies to identify and disrupt adversary networks.

But that set-up remained unclear for months. National Cyber Director Sean Cairncross said shortly after the strategy’s release that he was “not talking about private sector, industry or companies engaged in a cyber offensive campaign.” Instead, he described companies sharing information and capabilities that would enable the government to respond.

Some industry executives interviewed by Nextgov/FCW in April nevertheless predicted that the government would eventually contract with companies to support cyber operations. They also raised unresolved questions about legal authorities and how experts would define the fine line between creating obstacles for adversaries and hacking them offensively.

The administration moved further in May when its counterterrorism strategy explicitly identified offensive cyber operations as one of the tools Washington could use against threatening groups and the states that support them. That document offered scant details about how such operations would work.

Sherman argued that the U.S. shouldn’t let uncertainty about Russia’s cyber links stop it from taking action. The United States is overdue to reconsider assumptions about restraint and do more to counter Russia’s offensive cyber activity, he said, but a more aggressive posture does not make the underlying attribution decisions any easier.

Daniel said that ambiguity could give Washington leverage. Moscow could either let an operation against known criminals go unanswered or object and risk exposing its ties to them.

“The U.S. could use this formulation to call the Russians’ bluff — either acknowledge a relationship or let the group take the damage,” he said. But maintaining that bind would require the United States to choose its targets carefully. If a company inadvertently struck clandestine personnel from Moscow’s intelligence and security agencies, he added, the operation could create substantially greater consequences.

Cybercriminals routinely operate through hijacked servers and systems belonging to unwitting third parties, meaning companies carrying out hacks may have to distinguish targeted criminals from the infrastructure they have compromised.

“A lot is left to be determined on how the oversight is going to work, how the targeting is going to work,” Painter said. “That’s all supposed to be decided in 60 days,” he said, referring to the timeline the new policy must be developed by.

Painter said the best version of the program would be a tightly controlled process in which the government uses intelligence provided by companies and its own agencies to select legitimate targets. Companies would likely want written assurances that the government had approved a target and that their actions were covered by the program, he said.

The public directive does not explain how responsibility would be divided if a contractor followed an approved plan and the underlying intelligence proved wrong. Much of the operational process will also be governed by a classified annex.

Coordinating government decisions and private-sector activity in something approaching real time will itself be difficult, Daniel said. 

“I don’t know of any analogous precedent,” he added.

A DHS spokesperson did not respond to questions about how the administration would distinguish Russian cybercrime groups from state-linked actors or who would bear responsibility if a target were misidentified.

The department “looks forward to implementing President Trump’s directive to combat cyber-enabled transnational crime threatening Americans and our businesses,” the spokesperson said.

“Last year alone, cyber-enabled Transnational Criminal Organizations stole more than $20 billion directly from Americans through rampant fraud, ransomware, and extortion schemes,” White House spokesperson Lauren Bis said when asked the same line of questions. “The Trump administration is mounting an aggressive campaign to disrupt these illicit syndicates and dismantle them at the source.” 

The Justice and State departments did not provide comments. Russia’s embassy in Washington was also contacted.

The prospect of operations against pro-Russia cybercriminals carries a possible diplomatic dimension. Trump has continued direct engagement with Russian President Vladimir Putin and has sought to broker an end to the war in Ukraine. The two leaders agreed in July to maintain contact and speak again.

The administration has previously adjusted its cyber posture during negotiations with Moscow. Rep. Don Bacon, R-Neb., who chairs the House Armed Services Committee’s cyber panel, confirmed last year that Defense Secretary Pete Hegseth ordered a brief pause in U.S. Cyber Command operations against Russia as the administration pursued Ukraine talks. 

The memorandum requires coordination with the State Department, suggesting diplomatic consequences will be considered before an operation is approved. It does not say publicly how officials would weigh disrupting a Russian cybercrime group against other negotiations with the Kremlin.

“If there’s a decision made that says we’re being careful with Russia now because we’re in some sensitive talks, that will play into it,” Painter said. Companies could also “paint the target on themselves” and face Russian retaliation if their involvement became public, he added. Even if a company is required to keep its role secret, it wouldn’t prevent an adversary or another party from exposing it.

“I understand what they’re trying to do, and if it has really robust oversight, and including targeting and review and oversight of what they’re doing, it might work fine,” Painter said. “But there’s so much of a chance of that going wrong.”