Killnet is a pro-Russian hacktivist and Russia-aligned cyber actor that emerged around the start of Russia’s full-scale invasion of Ukraine in 2022. It is best known for politically motivated distributed denial-of-service operations against governments, public institutions, transportation entities, and other organizations in countries perceived as supporting Ukraine or opposing Russian interests. The group has also been described as a propaganda-oriented cyber militia that uses Telegram and other public channels to claim attacks, issue threats, amplify pro-Kremlin narratives, and encourage broader anti-Western cyber mobilization. Killnet’s operations have centered on disruptive activity rather than covert espionage. Its most consistently reported tradecraft is DDoS, including mass-coordinated campaigns against public-facing services. Reported targeting has included government and critical-infrastructure-related organizations in Lithuania, Estonia, Latvia, Poland, Romania, Czechia, Germany, the United Kingdom, the United States, Israel, and Ukraine. Public reporting has linked the group to retaliatory campaigns tied to geopolitical events, including support for Ukraine, sanctions, and symbolic political decisions by target states. In several cases, the operational impact described publicly was temporary service disruption rather than lasting compromise. The actor is widely characterized as Russia-based or Russia-linked. Some reporting portrays Killnet as an opportunistic pro-Russia actor that provides symbolic support, amplification, and target selection within broader anti-Western cyber ecosystems. It has also been referenced alongside other pro-Russian groups such as NoName057(16), XakNet, Cyber Army of Russia Reborn, and Russian Legion, also known as MONARCH. Killnet has additionally been cited in relation to collaboration or affinity with Anonymous Sudan, though the exact nature of those ties is not consistently established at the same confidence level as its DDoS activity. Killnet has been associated with a broader ecosystem of Russia-aligned cybercrime and hacktivist actors publicly pledging support for Russia and threatening entities that support Ukraine. Some accounts note that the name originally referred to a DDoS tool or service before becoming primarily associated with the hacktivist group. The group’s public posture, target selection, and messaging indicate a dominant ideological and geopolitical alignment with Russian state interests, even where formal state control is not conclusively demonstrated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An opportunistic anti-Western actor in the coalition, providing symbolic support, amplification, and target selection.
Killnet finally admits to working directly for the Kremlin
Named as part of the broader transnational hacktivist front contributing shared propaganda, repeated disruption, and leak operations.
Russian-aligned hacktivist ecosystem referenced via affiliates as a representative threat to public-facing World Cup-supporting services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.