KillNet is a pro-Russian hacktivist collective active since the early stages of Russia’s full-scale invasion of Ukraine in 2022. It is widely associated with politically motivated disruptive operations in support of Russian interests and anti-Western messaging rather than with advanced espionage tradecraft. The group is best known for publicly claimed distributed denial-of-service campaigns against government, public-sector, transportation, and other high-visibility organizations in countries perceived as supporting Ukraine or opposing Russia. Reported targets have included entities in the United States, the Baltic states, Poland, Romania, the United Kingdom, Israel, and other NATO-aligned countries. KillNet’s operations are characterized by overt propaganda, Telegram-based mobilization, public target lists, and rapid exploitation of geopolitical flashpoints. Its activity has included claimed attacks against election-related state government services in the United States, government websites in Romania and Lithuania, and broad disruptive campaigns across multiple countries’ critical infrastructure sectors. The group has also been cited as part of wider pro-Russian and anti-Western hacktivist ecosystems alongside actors such as NoName057(16), Cyber Army of Russia Reborn, XakNet, and MONARCH. Some reporting has described collaboration or close alignment with Anonymous Sudan, and at least one assessment has suggested Anonymous Sudan may function as a KillNet sub-group, though subgroup relationships should be treated cautiously. The actor’s core capability is service disruption through DDoS activity, often timed to political events, military developments, or symbolic dates. KillNet has also been associated in reporting with bot-based attacks and, in some accounts, access to dedicated sub-groups using IoT botnet infrastructure. Its campaigns are generally intended to create visibility, psychological pressure, and reputational impact rather than achieve covert persistence or strategic intelligence collection. Multiple government and industry assessments have therefore treated KillNet as a Russia-aligned disruptive threat actor and part of the broader cyber pressure apparatus surrounding the war in Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted DDoS attacks against U.S. state government websites in the run-up to the 2022 midterm elections.
An opportunistic anti-Western actor in the coalition, providing symbolic support, amplification, and target selection.
Killnet finally admits to working directly for the Kremlin
Named as part of the broader transnational hacktivist front contributing shared propaganda, repeated disruption, and leak operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.