Russian Intelligence Uses Latino Migrants for Sabotage in Europe

Russian military intelligence services are utilizing Facebook job postings and encrypted Telegram channels to recruit vulnerable Latin American migrants, particularly Colombians and Cubans, as disposable saboteurs for operations across Poland, the Czech Republic, Romania, and Lithuania.

The Anatomy of a Dispersed Sabotage Network

European public media investigative networks, working alongside judicial documents and police files, have uncovered a multi-tiered, compartmentalized network designed by Russian intelligence to maintain strict operational security. No single link in the chain knows the full scope of the mission. Spain serves as the primary logistical base and residence hub for coordinators, exploiting the freedom of movement within the European Union.

The operational framework relies on economic vulnerability. Handlers trawl open Facebook groups like “Latinos en Polonia” or “Cubanos en Rusia,” deploying seemingly innocuous gig-economy bait. Initial tasks—such as photographing specific critical infrastructure or industrial buildings—command small payouts ranging between 100 and 300 euros. Recruits who pass this initial vetting are moved to siloed Telegram chats. There, assignments escalate to arson and surveillance, with compensation leaping to 1.500 y 3.000 dólares, alongside pre-booked flights and hotel reservations.

Tracked Incidents Across Central and Eastern Europe

A string of physical attacks and reconnaissance missions mapped out by investigators reveals the operational footprint of these disposable agents:

  • May 23, 2024: Colombian national Andrés Alfonso de la Hoz set fire to a construction material warehouse in Warsaw, Poland, executing a secondary arson attack shortly after in Radom. Russian state-aligned channels immediately amplified false claims that the facilities functioned as a military logistics hub for Ukrainian forces.
  • June 6, 2024: De la Hoz targeted public transport buses in a Prague depot within the Czech Republic. Czech authorities apprehended him, resulting in an 8-year prison sentence.
  • July 28–30, 2024: Former Colombian military member Luis Alfonso Murillo Diosa flew from Medellín to Bucharest, Romania, conducting visual reconnaissance on a recycling plant and energy installations in Bragadiru. Romanian police intercepted him before he could ignite a local gas station. He is currently serving a six-year sentence.
  • September 2, 2024: Colombian national Gonzalo de Jesús Ramos Santos entered Lithuania to photograph TVC Solutions, a firm installing mobile radio-frequency spectrum analysis equipment destined for Ukraine.
  • September 8–17, 2024: Cuban-Spanish national Mayra Eukaris de la Lastra Nistal recorded additional footage of the Lithuanian facility. On September 17, Spanish citizen José López Aguilar and Colombian-Spanish dual national Andrés Felipe Díaz Rivas purchased fuel to execute the arson. Police patrols forced them to abort, and they were captured subsequently in Latvia.

Key Nodes and Coordinators in the Cyber-Physical Chain

Digital forensics and intelligence tracking place several key intermediaries at the center of this apparatus. Oemis Romagosa Durrutty, a Cuban-Russian resident of Petrozavodsk who previously worked as a salsa and bachata instructor, allegedly operates under multiple online aliases including “Dios,” “Adrian Zans,” and “Roma Martinelli.” Investigators identify him as the primary actor publishing Facebook job offers, coordinating travel, securing lodging, and disbursing transit funds.

Alexeis Pecora, based in Saint Petersburg, manages backend logistics, transmitting satellite imagery with designated escape routes and arranging transportation for the operatives. Meanwhile, colombo-español Carlos Alberto Legarda Devia operated from Spain as an intermediary nexus, coordinating fuel purchases, processing satellite imagery feeds, and ingesting field reports. Lithuanian courts have brought him to trial.

Strategic Intent: Paranoia and Probe Operations

According to the findings of the European public media investigation, the primary objectives of these proxy networks extend beyond isolated property damage. The directives aim to manufacture social paranoia, fracture civic trust in European governments, and erode public and political support for Ukraine.

EX CIA: Brutal reality of Russian intelligence tactics explained including assassinations & sabotage

Concurrently, these operations serve as empirical probes against Western security architectures. By deploying low-level, uninitiated agents, Russian handlers test the response velocity of local law enforcement, the efficiency of cross-border intelligence sharing among EU member states, and the hardening of critical national infrastructure defenses.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Natashquan Residents Report Healthcare Access Gaps in Citizen Survey

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.