Cyber Partisans is a Belarusian hacktivist group that emerged during the 2020 protests against the Lukashenko government. The group has described itself as being composed of IT specialists from Belarus’s technology sector and is widely associated with anti-regime and pro-Ukrainian political objectives. Its operations initially included defacement of Belarusian government websites, then expanded into intrusions against Belarusian state institutions and later Russian government and commercial targets. Cyber Partisans has also cooperated with Belarusian opposition structures such as BYPOL, whose current and former security-service members reportedly helped map internal agency structures and interpret stolen data. The group is known for targeting government, law-enforcement, surveillance, censorship, transportation, and industrial entities in Belarus and Russia. Reported compromises have included access to Belarusian government and security-related databases, surveillance systems, emergency-service recordings, and other sensitive state information. Cyber Partisans has also been linked to the retrieval and leak of data from Roskomnadzor, exposing Russian censorship and monitoring activities. In later operations, the group claimed destructive attacks against Russian- and Belarusian-linked industrial and transportation organizations, including wiping systems and disrupting operations. Cyber Partisans has been observed using custom malware and backdoors, including tooling that leverages Telegram for command and control and data exfiltration. Reported tradecraft includes initial access, persistence, data theft, destructive post-compromise activity, and operations against enterprise administration environments. The group has also been associated with targeting industrial enterprises and government agencies in Russia and Belarus using malware families such as Vasilek, as well as other implants and utilities. Public reporting characterizes the actor primarily as a hacktivist collective, though some reporting has alleged overlap between political activism and financial motives in parts of the broader Belarusian anti-regime ecosystem. High-confidence reporting supports Cyber Partisans primarily as a politically motivated Belarusian hacktivist actor rather than a ransomware operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hybrid formation combining hacktivism with financial motives.
Belarusian hacktivist group claiming disruptive intrusions against Belarusian industrial targets, including destructive actions (server/workstation destruction) after rapid privilege gain.
Allied with Silent Crow in the Aeroflot operation; declined to provide operational details to investigators/media per the report.
Cyber Partisans is a hacktivist group that, along with Silent Crow, claimed responsibility for a destructive cyberattack on Aeroflot, wiping thousands of servers and leaving anti-Putin messages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.