Solntsepek is a pro-Russian cyber persona presented as a hacktivist actor and has been linked in reporting to Russia’s Sandworm Group. It has been cited alongside other ostensibly independent pro-Russian personas used in the Russia-Ukraine conflict and is associated with destructive and influence-amplifying claims around cyber operations. Solntsepek publicly claimed responsibility for a major destructive attack and asserted large-scale destruction of victim systems, servers, and backups. The available information supports characterization of Solntsepek as part of the broader ecosystem of Russian-aligned cyber personas used to support wartime operations and messaging, rather than as a conventional financially motivated cybercriminal group. High-confidence reporting in the available material ties the actor to Russian operations and to destructive post-compromise activity, but does not provide sufficient corroborated detail to attribute a broader independent toolset, victimology, or organizational structure beyond its Russian alignment and claimed association with Sandworm.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Purported hacktivist persona described as a Russian intelligence-created false front to mask state operations as hacktivism.
Solntsepek is a threat actor linked to Sandworm, responsible for destructive cyberattacks, including wiping infrastructure in Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.