Killnet is a pro-Russian, Russia-linked hacktivist group active since the start of Russia’s 2022 invasion of Ukraine. The group is primarily associated with disruptive distributed denial-of-service (DDoS) operations against Western, NATO, and Ukraine-supporting targets, including government entities, critical infrastructure, airports, financial institutions, and other public-facing services. Reported targeting in the provided content includes Lithuania, Latvia, Romania, Estonia, Czechia, Poland, the UK, the US, Israel, and other Western organizations. The group publicly claims operations through Telegram and uses propaganda and anti-Western or anti-Israel messaging to amplify impact. In the content, Killnet is described as conducting or claiming high-profile DDoS attacks against Lithuanian government and business websites, Romanian government websites, Latvian targets, Estonian institutions, a US airport, and the Israeli government website. The group has also been cited as part of broader pro-Russian hacktivist activity extending the Russia-Ukraine conflict into cyberspace. Killnet’s tradecraft in the provided content centers on bot-based denial-of-service activity. One report states its modus operandi resembles abuse of computational resources to direct bot-based DDoS attacks against Western representative organizations. The content also notes that Killnet has used or rented botnet infrastructure and that, unlike some volunteer-heavy collectives, it has included dedicated sub-groups using IoT botnet infrastructure such as Mirai. The group is repeatedly associated with DDoS-focused operations rather than sophisticated espionage tradecraft. The content also describes Killnet as part of a wider ecosystem of Russia-aligned actors and affiliates. It is mentioned alongside NoName057(16), Cyber Army of Russia Reborn, Sandworm, XaKnet/Xaknet Team, and other Russia-aligned groups. Some reporting in the content notes collaboration or close ties with Anonymous Sudan, and one source cited in the content assesses Anonymous Sudan as likely a sub-group of Killnet. Killnet is also referenced as having later become a more mainstream attackers-for-hire service. Known aliases directly reflected in the content: Killnet.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of the broader transnational hacktivist front contributing shared propaganda, repeated disruption, and leak operations.
Russian-aligned hacktivist ecosystem referenced via affiliates as a representative threat to public-facing World Cup-supporting services.
Claimed to have obtained Lockheed Martin employee personal information, including email addresses and phone numbers.
Group involved in similar opportunistic cyber activity aligned with the conflict's anti-US and anti-Israel hacktivist wave.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.