ZeroFox Intelligence Flash Report - Buyer Seeks Baltic Access on DDW Amid Hybrid War Surge
|by Alpha Team

ZeroFox Intelligence Flash Report - Buyer Seeks Baltic Access on DDW Amid Hybrid War Surge
Product Serial: F-2026-09-28a
TLP:CLEAR
In this Flash Report, ZeroFox researchers discuss a recent attempt to purchase unspecified network access in the Baltic states and how it is linked to Russian hybrid operations designed to weaken European support for Ukraine.
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 16, 2026, a relatively new and positively trending threat actor “root_zero” posted on the predominantly Russian-language dark web forum Exploit seeking to purchase unspecified network access to the Baltic states of Estonia, Latvia, and Lithuania; the timing of the post is likely linked to Russian hybrid operations designed to weaken European support for Ukraine.
- Although the actor’s motivations and capabilities remain unclear, there is a roughly even chance root_zero intends to obtain information on pro-Russian cybercriminals under the guise of coordinating an espionage campaign or monetizing initial access.
- The past two months have marked an escalation for hybrid activities across Europe, with the Baltic states—along with other Russian-border and former Soviet nations—bearing the brunt of Russian hybrid and saber-rattling campaigns.
Tags: tlp:clear, dark web, geo-political, threat actor, eu/russia