Silent Crow is a pro-Ukraine hacking group that has claimed responsibility for several cyberattacks against Russian targets. Reported activity includes a claimed breach of Rosreestr, Russia’s state property registry, and joint claims with the Belarusian Cyber Partisans/Cyber Partisans BY for the July 2025 Aeroflot attack. In reporting on the Aeroflot incident, Silent Crow and the allied Belarusian Cyber Partisans were described as claiming a yearlong operation that deeply penetrated Aeroflot’s network, paralyzed operations, caused cancellation of more than 100 flights affecting roughly 20,000 passengers, and involved destruction of IT infrastructure and exfiltration of sensitive data. Additional reporting cited claims that thousands of servers were wiped and that anti-Putin messages were written onto files. Silent Crow has also been mentioned among groups and clusters in the pro-Ukraine ecosystem. Russia is seeking to designate Silent Crow and the Belarusian Cyber Partisans as extremist organizations, which would ban their activities in Russia. No sub-groups for Silent Crow are directly identified in the provided content. Known alias in the provided content: silent_crow.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a Ukraine-aligned cluster with precedent for targeting Russian entities, but not attributed to the incidents discussed.
Pro-Ukraine hacking group that claimed multiple cyberattacks against Russian targets, including Rosreestr and the 2025 Aeroflot incident alongside Belarusian Cyber Partisans.
Group associated with a claimed breach of Russian airline systems and large-scale data exfiltration.
Claimed responsibility for a disruptive intrusion against Aeroflot, reportedly leveraging third-party contractor access (Bakka Soft) to regain entry, establish persistence, move into Active Directory, obtain high-privilege accounts, and deploy multiple malware tools; also reported to have breached a Rostelecom contractor and leaked data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.