Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇷🇺 RU

Wagner

Also known asWagner

Wagner Group is a Russia-affiliated mercenary organization closely tied to Russian state interests and widely described as the most active Russian mercenary organization. The content identifies Yevgeny Prigozhin as its founder/head and a close Putin ally. Although not formally connected to the Kremlin, Wagner is described as operating in coordination with Russia to advance Russian national interests while providing Moscow plausible deniability. The group has been linked to shell-corporate structures outside Russia, access to sophisticated weapons and intelligence through Russian security elements, and disinformation efforts tied to Prigozhin-linked operatives. Wagner has operated in Ukraine, Syria, Libya, Venezuela, and multiple African states, and the content notes that it has been replaced in parts of Africa by the Russia-run Africa Corps, which is described as largely institutionalizing Wagner’s intervention model. In Ukraine, the content states that Wagner fighters operated alongside separatist forces in Donbas and that Wagner teams were reportedly sent to Kyiv in 2022 with orders to kill key Ukrainian leaders, including President Volodymyr Zelenskyy. Reporting cited in the content also describes Russian forces including Wagner personnel and special forces in covert operations, including alleged use of civilian clothes, possible use of Ukrainian uniforms, and captured vehicles, raising concerns around sabotage, decapitation operations, and perfidy. The content further notes that Russian forces later adopted infantry tactics derived from Wagner that treated infantry as expendable and relied on numbers plus fires. In Syria, Wagner supported Russian and Syrian regime objectives and participated in offensive combat operations; the content also references the 2018 clash in Syria in which U.S. forces fought several hundred Wagner members supporting pro-Syrian regime forces. In Libya, Wagner supported a Russian-aligned faction in the civil war and was described as providing immediate battlefield advantage. In Africa and the Sahel, Wagner is described as a key instrument of Russian influence, combining military support, regime protection, and disinformation in exchange for access to resources. The content specifically cites deployments in Mali beginning in 2021, growth from roughly 1,000 to about 2,500 fighters, and involvement in abusive counterterrorism operations alongside Malian forces. Reported abuses attributed to Wagner-linked or Russian partner operations in Mali include torture, rape, forced disappearances, extrajudicial killings, and widespread abuses against civilians. The content also states Wagner-linked mercenaries were involved in influence operations and military special operations across Africa on behalf of Russia. The content additionally links Wagner to hostile activity in Europe. It cites a UK case in which Dylan Earl received a 17-year sentence for masterminding an arson campaign for Russia’s Wagner Group, and Polish reporting that Russian services prefer recruits with law-enforcement or military backgrounds, including mercenaries from organizations such as Wagner, for more professional sabotage cells. Known aliases in the provided content: Wagner, Wagner Group, ChVK/PMC Wagner (ЧВК «Вагнер»). Related successor structure mentioned in the content: Africa Corps.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

1 of 15 tactics1 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping1

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.