Why 44% of Web Attacks on Russian Companies Are Now Multi-Stage

Web attacks against Russian companies are shifting from single, short-lived hits to prolonged multi-stage campaigns, according to a study by cybersecurity firms WMX and Servicepipe reviewed by Vedomosti. The researchers found that 44% of web attacks on Russian companies in the first half of 2026 were multi-stage, compared with the same period a year earlier. Total attacks on the application layer of corporate websites and applications reached 849.7 million, up 27% year on year.

A multi-stage attack is not one event but a sequence: reconnaissance, disabling part of the infrastructure, and then continued disruption of individual departments within the company. Four Russian security vendors — Kaspersky Lab, RED Security, Garda and Elvis-plus — told Vedomosti they see the same trend.

Garda's Luka Safonov described how a typical campaign develops. Attackers first enter a company's network through phishing, using fake sites or emails to steal passwords, personal data or bank card numbers. They then raise the privileges of the compromised account, establish themselves inside the infrastructure, move between systems, and only at the end steal data, encrypt resources or disrupt operations. Safonov warns that hackers can remain inside a company for about a year in this mode.

The practical implication for Russian companies is that stopping one attack no longer proves a network is safe. The question is no longer only 'did we block the hit?' but 'how far inside did the attacker get before anyone noticed?'

Advertisement

What the Multi-Stage Shift Means for Defenders and Security Vendors

What the WMX and Servicepipe data actually shows

The most concrete part of the picture is the volume: 849.7 million application-layer attacks in the first half of 2026, 27% above a year earlier, with 44% of web attacks involving multiple stages. The second figure matters more than the first. A multi-stage campaign spreads its actions across time and systems, so counting it as a single attack understates the effort needed to contain it. The story does not disclose the study's methodology or the previous year's multi-stage share, which limits how precisely the shift can be measured.

Why attackers are adding stages

The explanation offered by the research, and echoed by the four vendors, is that stronger baseline defenses are forcing attackers to work harder. If a single exploit no longer reliably works, the rational alternative is a chain: phishing for an account, privilege escalation, lateral movement, and a final theft or disruption stage. This reading fits the mechanics described by Safonov, where the initial compromise is only the beginning of a campaign that can last about a year.

What this means for Kaspersky Lab, RED Security, Garda and Elvis-plus

The vendors confirming the trend have a commercial interest in it: multi-stage attacks increase demand for detection-and-response tools, threat hunting and incident investigation, all higher-value services than basic web filtering. That does not make their confirmation invalid, but it is a reason to weigh the independent count from WMX and Servicepipe alongside the vendors' statements rather than treat either as neutral.

Where the risk now sits

For Russian companies, the practical shift is that perimeter defenses now cover only the first links of the chain. Once an account is compromised, the campaign continues through privilege escalation and lateral movement, which are harder to detect and more expensive to investigate. Companies relying on single-layer web protection and weak identity controls are most exposed, because the reported attack path depends on credential theft as the entry point.

How Russian Companies Should Adapt to Multi-Stage Web Attacks

  • Assume one weak credential can start a campaign: phishing is the reported entry point, and the next step is privilege escalation, so privileged accounts should be protected with multi-factor authentication as a priority.
  • Plan for long dwell time: the Garda expert puts internal presence at up to a year, so detection should focus on anomalous behaviour inside the network, not only alerts at the perimeter.
  • Re-check application-layer capacity and filtering rules: the 27% increase to 849.7 million application-layer attacks shows traffic pressure on web-facing infrastructure is still rising.
  • Treat the study as a baseline, not proof: because WMX and Servicepipe produced the data and four vendors with products to sell confirmed the trend, security buyers should validate multi-stage detection claims in their own environment.

Risk & Opportunity Assessment

Commercial RiskMediumMulti-stage campaigns can end in data theft, encryption or operational disruption, and the reported 44% share plus a dwell time of up to a year puts a large part of Russian corporate infrastructure in their path.
Competitive RiskLowNo individual company is named as a victim and no market-share shift is reported; the main effect is to strengthen demand for vendors with detection and response capabilities.
Regulatory RiskLowThe article cites no regulatory action; exposure is indirect through potential data-protection obligations if stolen data includes personal information.
Reputation RiskMediumThe described endgame of data theft, encryption and operational disruption is highly visible if it becomes public, though no specific victims are named.
Technology DisruptionMediumThe rise of multi-stage attacks is itself a technology shift, forcing security teams to combine identity, network and endpoint monitoring instead of relying on a single layer.
Commercial OpportunityMediumSecurity vendors including Kaspersky Lab, RED Security, Garda and Elvis-plus stand to gain as multi-stage attacks increase demand for advanced detection and response services.