Hybrid warfare is the threat of the moment across Europe, and one of the startups building tools to help countries defend themselves from multi-domain attacks has raised some funding to expand.
Osavul, a startup founded by Ukrainians that builds digital systems that detect suspicious physical or digital activity when it starts to manifest in its earliest stages — in the digital world — has raised €8.5 million ($10 million) in a Series A round of funding. 33N Ventures led the round, with participation from Balnord, G+D Ventures and existing investor 42CAP. The company, which is headquartered in Luxembourg but with operations in multiple countries, has raised €12 million to date.
Osavul’s CEO Dmytro Plieshakov says it has built “largely agentic” systems that track more than 1 billion data points on a monthly basis across a range of channels and covering more than 100 countries, and it uses that data to build patterns and pictures of nefarious activity.
To date, Osavul has focused on working with nations and defence organisations, with government customers in 10 countries, including NATO. The plan now is to use the new funding to continue enhancing its product, and to widen its aperture to apply that work also to businesses in critical industries and larger enterprises.
Nomadic intelligence
Plieshakov and co-founder Dmytro Bilash (chief business development office, right and left respectively) say they named the company after the term used in the 16th and 17th centuries for an intelligence officer in the Cossack army — the nomadic group that traces its roots to what is now Ukraine and known at that time for being effective border defenders. The startup possesses some of the osavul ethos in how it has arrived at the business it’s in now.
The pair are repeat entrepreneurs who have worked together for years.
But in early 2022, they were not building cybersecurity products; they were into data science and how it related to advertising technology. Adtech giant Perion had acquired their previous startup, Captain Growth, in 2019, and they were just leaving the firm after completing their earn-out, doing some travelling and “living the digital nomadic lifestyle,” in the words of Plieshakov.
Yet as with many in Ukraine, Russia’s full-scale invasion drastically changed the course of their careers.
Bilash’s own home was hit by Russian missiles at the start of the war, and so, when the Ukraine government early on started connecting with technologists to explore how they might help in defence efforts, the pair answered the call.
Some (a lot) of that outreach led to the start of drone ecosystem and other military endpoints, but for Plieshakov and Bilash, it went into a different area that was very adjacent to what they were already doing in adtech: disinformation.
There is some logic to this. Prior to the invasion, disinformation had already emerged as a problem across Europe, with nefarious groups, some linked to Russia, meddling on social media and other channels to influence public opinion around critical elections, among other things. There were already links being drawn between how the levers of adtech were being exploited by malicious actors intent on disinformation.
But the full-scale invasion saw a huge increase in the amount and sophistication and ultimate motivations were behind disinformation, turning that activity from a pernicious problem into arguably one of most stubborn vectors of grey-zone warfare.
So that became the first focus for Osavul, which initially built products that tapped into the founders’ expertise and experience in data science and adtech: monitoring vast amounts of online information across social media, messaging platforms, chatrooms, publicly available information, and more to understand sentiment and what engineered ideas were taking hold.
‘No one specific vector should be siloed’
Over the last several years, the aim of Osavul has evolved and disinformation now is not the only endpoint. The company currently looks at how any information can contribute to a picture of a much wider range of threats, be they digital or physical.
“Hybrid means multiple things and that was our biggest insight,” Plieshakov said in an interview with Resilience Media. “No one specific vector should be siloed.”
This matches up with how hybrid warfare has also evolved. Russia and its allies today employ a range of tactics to carry out attacks intended to destabilise countries supporting Ukraine. This has extended well beyond disinformation to involve activating “agents” to carry out arson; air and sea incursions of unclear intent; and cyberattacks targeting critical industries, among other things.
The fact that the whole world relies on digital services to some extent underscores just how big the attack surface is for adversaries to exploit — a problem laid bare more recently with the advances we are seeing with AI agents. But it also lays out the breadcrumbs that hybrid threat hunters might track to figure out what is going on.
In Osavul’s case, it does this through three layers, Plieshakov explained: collecting information, data enrichment to extract insights, and then agentic layers to put points together to reason how they fit together.
Osavul’s belief is that, alongside the many cybersecurity solutions that exist today to protect assets, there are also opportunities for companies that are building ways to read signals to understand how and what is being planned in much earlier stages to better prepare against sabotage, cognitive operations, and espionage.
Not least because the other set of cyber solutions are not always perfect.
“Hybrid risks are not well covered,” said Bilash. “There are gaps in the industry, and it’s not just a cyber threat. This is something new, and there is a need for new intelligence companies that know how to deal with it.”
Osavul is not extremely forthcoming, as you would guess, about how it works or when it has been effective. It has, however, published one case on its site about how its Janus product detected an espionage campaign against NATO months before it kicked off in earnest — giving the organisation a head start in successfully defending against it.
The company is also not very forthcoming about how it’s doing as a business: no disclosure of revenues or valuation — although with normal dilutions, it will be most likely a modest under or around $50 million right now. Plieshakov noted that business is growing, with contract revenue up four-fold in the last year.
Lead investor 33N, which is a cyber specialist, saw an opportunity to get in early with a strong company in a space it has been watching for a while, looking for investment opportunities in it.
“There is not a single physical attack that doesn’t start somewhere in the digital world. That can involve preparation and much more,” said Carlos Alberto Silva, the managing partner at 33N.













