Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
hacktivist-operationoperational-disruptiongovernment-diplomatic-threatcritical-infrastructure-threat

Hacktivist Cyber Operations Escalate Amid Geopolitical Tensions

Updated 3mo agoFirst seen Feb 2, 20263 sources

A newly formed Russian-aligned hacktivist coalition calling itself Russian Legion (reportedly comprising Cardinal, The White Pulse, Russian Partizan, and Inteid) announced “OpDenmark,” a campaign of DDoS attacks intended to disrupt Danish government services and critical infrastructure and pressure Denmark to reverse military support for Ukraine. Reporting indicates the group issued an ultimatum tied to Denmark’s planned 1.5 billion DKK aid package, followed by service disruptions across multiple Danish organizations, including repeated targeting of the energy sector; analysts characterized the actor as state-aligned but not state-funded, using disruption and psychological pressure rather than confirmed destructive intrusions.

Separately, a new hacktivist group, Punishing Owl, claimed a breach of a Russian government security agency, publishing stolen documents and using DNS manipulation to redirect traffic to attacker-controlled infrastructure hosting the leak and a manifesto. The operation reportedly expanded into business email compromise against partners/contractors and included tooling such as the ZipWhisper PowerShell stealer, with lures using password-protected ZIPs and disguised LNK files to execute PowerShell downloaders. An additional opinion piece highlighted a broader rise in energy infrastructure cyber operations (including referenced events affecting Poland and Venezuela) but did not provide corroboration or direct linkage to the Denmark DDoS campaign or the Punishing Owl intrusion.

Share:
Hacktivist Cyber Operations Escalate Amid Geopolitical Tensions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 4, 20265mo ago

Russian Legion announces a new wave of attacks on Denmark

By 2026-02-04, reporting indicated Russian Legion had announced a specific time for another wave of attacks against Denmark. The campaign continued to combine DDoS activity, public threats, and psychological operations to amplify fear and media attention.

Feb 2, 20265mo ago

Technical details of ZipWhisper stealer are disclosed

Researchers disclosed that ZipWhisper harvested browser credentials, cookies, and saved passwords, staged the data in the Temp directory, and uploaded it to a command-and-control endpoint. The report also noted code comments suggesting AI tooling may have been used to generate parts of the malware script.

Punishing Owl expands intrusion into BEC against partners and contractors

Following the initial compromise, Punishing Owl used email accounts created within the victim's domain to target the agency's partners and contractors in a business email compromise campaign. Messages sent from Brazilian infrastructure carried password-protected ZIP files containing disguised LNK files that launched PowerShell to download the ZipWhisper stealer.

Jan 30, 20265mo ago

Russian Legion begins OpDenmark disruptions after deadline passes

After the 48-hour deadline expired, Danish companies and public sector organizations reported service disruptions attributed to Russian Legion's OpDenmark campaign. The group and associated figures posted screenshots claiming Danish websites had been taken offline, with repeated targeting especially noted in the energy sector.

Jan 28, 20265mo ago

Russian Legion issues ultimatum to Denmark over Ukraine aid

On 2026-01-28, Russian Legion warned Denmark via Telegram to withdraw its planned 1.5 billion DKK military aid package to Ukraine within 48 hours. The group threatened to escalate from DDoS activity to broader cyberattacks if Denmark did not comply.

Jan 27, 20265mo ago

Russian Legion member reportedly targets Danish healthcare portal

Earlier in the week before the main ultimatum, a Russian Legion member known as Inteid reportedly conducted preliminary attacks against Denmark's healthcare portal sundhed.dk. The activity indicated the alliance's ability to disrupt healthcare-related online services.

Russian Legion announces formation

On 2026-01-27, the pro-Russian hacktivist alliance Russian Legion announced its creation. The group was later assessed by Truesec as likely state-aligned but not directly state-funded.

Dec 12, 20256mo ago

Punishing Owl claims breach of Russian security agency and leaks data

On 2025-12-12, the newly identified hacktivist group Punishing Owl publicly claimed it had compromised a Russian government security agency and leaked internal documents. The group also altered the victim's DNS to create a subdomain that redirected traffic to a Brazil-hosted server serving the stolen data and a political manifesto.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Malware
1 linked
Affected products
2 linked
TelegramPowershell
Organizations
3 linked
TruesecGBHackers NewsMega
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.