Large-scale spyware operation detected in Serbia
SurveillanceComments
We should also consider if this was a single operation or a series of smaller, coinciding campaigns using the same kit. The reported scale might just be an aggregation of several disparate actors using the same commercial software.
I am not so sure about the stability angle. Most local administrations in the Balkans are already habituated to these kinds of intrusions, so this might be more about the scale than a shift in how things actually function on the ground.
The OP is correct about the infrastructure requirements. To maintain this volume of C2 (command and control) traffic without detection usually requires a tiered proxy network or bulletproof hosting services that operate outside of standard jurisdictional oversight.
If the local administrations are already used to this... does that mean the software is becoming a standard part of the official toolkit... or is it still mostly clandestine?
It is worth noting that the detection itself comes from a stronger coalition of regional cybersecurity watchdogs. This suggests that the transparency and ability to spot these operations are improving, even if the operations themselves are growing.