Zarya is a pro-Russia hacking group publicly linked to a February 2023 intrusion affecting an unnamed Canadian gas pipeline operator. Reporting on the incident stated that the group had access to the operator’s infrastructure and that the operation was intended to economically harm the company. Leaked intelligence cited in public reporting further indicated concern that the intrusion could have created conditions for physical damage, including a potential explosion, although Canadian authorities stated there was no physical damage to energy infrastructure. The same reporting said Zarya communicated with Russia’s Federal Security Service (FSB) regarding the incident and awaited further instructions, suggesting at least alleged coordination or tasking overlap with Russian state interests. Based on the available high-confidence information, Zarya should be characterized as a pro-Russian actor associated with intrusion activity against Western critical infrastructure, particularly in the energy sector. Publicly available detail on its broader tooling, long-term campaign history, sub-groups, or stable malware ecosystem remains limited.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in reporting on Russia's cyber tactics.
Pro-Russia hacking group implicated in a February 25, 2023 cyber incident against an unnamed Canadian gas pipeline operator; per leaked intelligence reporting, had access to pipeline operator infrastructure and was allegedly coordinating with Russian intelligence regarding potential physical effects, with stated intent to economically damage the company.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.