Serbia and Montenegro: Convenient Gateways for Russia’s Cyber War?

RKS NEWS
RKS NEWS 8 Min Read
8 Min Read

A new investigation by the Balkan Investigative Reporting Network (BIRN) raises uncomfortable questions about Serbia and Montenegro’s role in the increasingly sophisticated infrastructure supporting Russian-linked cybercrime and disinformation operations across Europe.

According to BIRN’s investigation, companies registered in Serbia and Montenegro have become connected to networks of internet infrastructure previously associated with sanctioned Russian providers, cybercriminal groups and Russian influence operations.

The picture that emerges is deeply troubling: when Russian-linked companies are sanctioned or exposed, their digital infrastructure can be moved through smaller companies and different jurisdictions, allowing the networks to survive under new names and in new locations.

And Serbia appears repeatedly in that chain.

One of the central cases examined by BIRN is eServer, a Russian-owned web-hosting company registered in the Serbian city of Kruševac. Its owner, Maxim Azarov, has links to internet infrastructure that subsequently became associated with companies such as Aeza Group and Stark Industries Solutions — Russian providers that have faced Western sanctions over alleged support for cybercriminal activity and Russian state-aligned cyber operations.

The significance is not simply that Russian nationals are doing business in Serbia.

The bigger concern is what happens to the digital infrastructure passing through these companies.

BIRN traced IP ranges between companies, jurisdictions and providers, showing how internet resources can move from one entity to another after sanctions or scrutiny. Such arrangements can obscure the ultimate ownership and users of the infrastructure, making it considerably harder for investigators and cybersecurity agencies to establish where malicious activity actually originates.

This is precisely the kind of loophole Russia has exploited to sustain its broader cyber and information warfare capabilities.

When one provider is sanctioned, the infrastructure does not necessarily disappear. IP addresses can be transferred. Companies can be replaced. Servers can be moved. New intermediaries can appear.

The result is a digital shell game in which the Russian origin of an operation becomes increasingly difficult to see.

Serbia’s growing role raises serious questions

BIRN identified multiple IP ranges associated with Serbia and Belgrade that were connected to providers previously linked to the Russian bulletproof-hosting ecosystem.

The investigation also identified Russian nationals who established hosting businesses in Serbia while maintaining connections to Russian companies and networks associated with cyber operations and disinformation campaigns.

One particularly striking example involves Alexei Fedorov, whose companies in Serbia are linked to infrastructure that researchers have associated with the Russian Doppelganger disinformation operation and other cyber-related networks.

Another case involves Aleksandr Shmalko, who registered a company called Castles in Novi Sad. BIRN found connections between the company’s infrastructure and networks that researchers have linked to Russian cyberattacks, the Doppelganger campaign and the Qilin ransomware group.

Again, this does not mean that every Serbian-registered company identified by BIRN is itself carrying out cyberattacks.

But it raises an unavoidable question:

Why does Russian-linked infrastructure repeatedly find a convenient operational environment in Serbia?

That question deserves much more than vague assurances about individual companies having anti-cybercrime policies.

Montenegro is part of the wider problem

The investigation also points to Montenegro, placing both countries within a wider Balkan network through which IP resources and digital infrastructure can be transferred.

The problem for European security is obvious.

If sanctioned Russian infrastructure can simply move through companies registered in Serbia or Montenegro, then the effectiveness of Western sanctions is weakened.

The geography changes.

The corporate name changes.

The IP address changes.

But the underlying network can remain operational.

That is precisely why the issue should not be dismissed as an ordinary business or technical matter.

Europe cannot afford a Balkan loophole

Russia’s cyber warfare does not stop at the Ukrainian battlefield.

Cyberattacks, ransomware, disinformation campaigns, malware infrastructure and covert influence operations form part of a broader strategy designed to undermine European institutions, businesses, governments and democratic societies.

The West has responded with sanctions against Russian cyber actors and infrastructure providers.

But sanctions only work if there are consequences for attempts to circumvent them.

That is where Serbia and Montenegro face an uncomfortable test.

Both countries have repeatedly presented themselves as European partners committed to regional stability and security. Yet investigations such as BIRN’s raise legitimate concerns about whether their regulatory and enforcement systems are sufficiently robust to prevent their territories and digital infrastructure from becoming convenient transit points for Russian-linked networks.

This is especially sensitive for Serbia, given its longstanding political and strategic relationship with Moscow and its complicated position between Russia and the European Union.

Belgrade cannot demand recognition as a serious European security partner while ignoring credible evidence that Russian-linked digital networks are operating through companies registered on Serbian territory.

And Montenegro cannot simply assume that being a NATO member makes it immune from becoming part of Russia’s wider cyber ecosystem.

Cybersecurity is not about political declarations. It is about who is allowed to operate, who is investigated, who is sanctioned and who is held accountable.

The question Belgrade and Podgorica must answer

The central issue is not whether Serbia or Montenegro are themselves “running” Russian cyber operations. BIRN’s investigation does not establish that.

The issue is whether Russian-linked actors are exploiting corporate structures and internet infrastructure in these countries to make their activities harder to detect and disrupt — and whether the authorities are doing enough to stop it.

That is a serious national-security question.

Europe is already confronting Russian hybrid warfare on multiple fronts. If companies operating from the Balkans can provide the infrastructure through which sanctioned Russian networks continue to function, then the Balkans risk becoming an unintended — or tolerated — loophole in Europe’s defenses.

Serbia and Montenegro therefore need to do more than deny direct involvement.

They need to demonstrate that they are actively investigating these networks, enforcing sanctions, scrutinizing suspicious corporate structures and preventing their territories from being used as safe transit routes for Russian-linked cyber infrastructure.

Because when sanctioned Russian networks simply reappear under different corporate names and through Balkan infrastructure, the problem is no longer just in Moscow.

It is also a question of what Belgrade and Podgorica are willing to tolerate.