XakNet, also referred to as The XakNet Team and stylized as XaKnet, is a Russia-aligned hacktivist and cybercriminal persona active in the context of Russia’s war against Ukraine. Public reporting has associated the group with pro-Russian disruptive and hack-and-leak activity targeting Ukrainian and Western entities, and some assessments have described XakNet as part of a broader ecosystem of Russian-aligned non-state actors used to amplify pressure on opponents of Russia. The group has also been cited alongside Killnet and other Russia-aligned collectives as a potential threat to critical infrastructure organizations, particularly those perceived as supporting Ukraine. XakNet is known primarily for opportunistic intrusion claims, data theft claims, leak operations, and propaganda-oriented cyber activity rather than for uniquely attributed advanced tradecraft. A notable publicly reported operation involved a claimed breach of the Ukrainian Ministry of Foreign Affairs in 2022, followed by the release of exfiltrated documents and crowdsourced analysis of the stolen material through social channels. Reporting has also linked XakNet to cyber activity directed at Ukrainian and Western targets during the broader wartime mobilization of pro-Russian hacktivist groups. Multiple government and industry assessments place XakNet in the category of Russia-aligned hacktivist or cybercriminal actors rather than a formally attributed Russian intelligence service unit. However, some reporting has asserted that Russian intelligence services have cultivated or operated ostensibly independent hacktivist personas, including XakNet, to provide deniability, shape information operations, and coordinate patriotic cyber activity. High-confidence public attribution tying XakNet directly to a specific Russian state organ is not currently available. Operationally, XakNet fits the pattern of pro-Russian wartime cyber actors that combine network intrusion claims, exfiltration, public leaks, influence messaging, and support for distributed denial-of-service campaigns conducted by aligned communities. The group is commonly discussed alongside Killnet, Cyber Army of Russia Reborn, Solntsepek, and other pro-Russian personas active since the 2022 invasion of Ukraine. Its targeting has centered on Ukrainian government interests and entities in countries backing Ukraine, with effects aimed as much at publicity, intimidation, and narrative amplification as at sustained clandestine access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in reporting on Russia's cyber tactics.
Purported hacktivist persona described as a Russian intelligence-created false front to mask state operations as hacktivism.
Russian-aligned group referenced as conducting cyber-attacks against Ukrainian and Western targets.
Russian cybercriminal group highlighted in the alert as part of the broader Russian cyber threat landscape.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.