KillNet is a pro-Russian hacktivist collective active since Russia’s full-scale invasion of Ukraine in 2022. It conducts politically motivated, relatively low-sophistication distributed denial-of-service operations against organizations perceived as anti-Russian or supportive of Ukraine, using public claims and propaganda to amplify the perceived impact of temporary service disruptions. The group coordinates and recruits through Telegram, has used publicly available attack scripts, open proxies, volunteer participation, and bot-based infrastructure, and publicly announces target lists and claimed operations. KillNet has targeted government entities, public-facing critical-infrastructure services, healthcare organizations, airports, and energy-related entities. Documented or credibly assessed campaigns have affected targets in the United States, Ukraine, Israel, Romania, and Latvia. Its activity against U.S. state-government and airport websites, for example, caused website availability issues without meaningful disruption to airport operations. The group has also claimed high-profile attacks against Israeli public-sector websites and conducted attacks against Romanian government services following political developments involving Russia and Ukraine. KillNet’s primary operational objective is disruption and psychological or reputational effect rather than destructive compromise. Its operations are aligned with pro-Kremlin geopolitical narratives, but the available information does not establish that KillNet is formally part of the Russian state. The group has collaborated or coordinated publicly with other hacktivist brands, including Anonymous Sudan, and has been associated with the broader pro-Russian hacktivist ecosystem alongside NoName057(16).
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a pro-Russian hacktivist collective whose activity aligns with Russian geopolitical interests and state-aligned narratives.
Conducted DDoS attacks against U.S. state government websites in the run-up to the 2022 midterm elections.
An opportunistic anti-Western actor in the coalition, providing symbolic support, amplification, and target selection.
Killnet finally admits to working directly for the Kremlin
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.