CyberBerkut is a pro-Russian hacktivist persona and influence operation active since 2014, widely assessed as linked to Russian military intelligence (GRU). It emerged during the Russia-Ukraine conflict and has been used to provide plausible deniability for cyber and information operations aligned with Russian state interests. Security reporting and government assessments have associated CyberBerkut with GRU-linked activity and, in some cases, with the broader APT28/Fancy Bear ecosystem. CyberBerkut has primarily targeted Ukrainian government institutions, election-related entities, ministries, banks, media, and Western organizations associated with support for Ukraine, including NATO-related institutions. Its operations have included website defacements, distributed denial-of-service attacks, network compromise, data destruction, theft and publication of stolen material, attempted manipulation of election-related information, and coordinated propaganda or disinformation activity. During the 2014 Ukrainian presidential election period, CyberBerkut was associated with malicious activity against the Ukrainian Central Election Commission, including compromise, disruptive actions, and attempted dissemination of false election results. Beyond disruptive intrusions, CyberBerkut has functioned as a leak and influence brand. It has published hacked or purportedly hacked materials, amplified anti-Ukrainian narratives, and circulated fabricated or manipulated media intended to discredit the Ukrainian government, Western institutions, and Kremlin opponents. Reported activity includes anti-NATO messaging, false-flag style propaganda, and participation in broader Russian active-measures patterns in which a nominally independent hacktivist identity is used to mask or soften attribution to state operators. Known aliases include cyberberkut and cyber_berkut. CyberBerkut is best understood not as an ordinary independent hacktivist collective, but as a pro-Russian operational persona used for cyber disruption, hack-and-leak activity, and information warfare in support of Russian geopolitical objectives, especially against Ukraine and related Western targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Moscow hacking collective involved in cyber operations during Russia’s invasion of Ukraine, including website defacements in Ukraine.
Conducting disinformation and influence operations using fabricated videos and photos, including efforts to discredit Ukrainian authorities and a Russian opposition figure.
Russian-aligned hacker group blamed for attacks on Ukrainian ministries and the 2014 Ukrainian presidential election; presented here as the Russian counterpart to the Ukrainian Cyber Alliance.
Group cited as having disrupted Ukrainian elections (2015), used as precedent for Russia-linked election interference via hacking.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.