Belarusian Cyber Partisans is a Belarusian hacktivist and opposition-aligned cyber group that emerged after the 2020 protests against Alyaksandr Lukashenka. The group is widely known for conducting politically motivated intrusions and disruptive operations against Belarusian state institutions and, later, Russian government and critical-sector targets in connection with Belarus’s support for Russia’s war against Ukraine. It is commonly referred to as Belarusian Cyber Partisans, with variants including Belarusian Cyber-Partisans and Belarusian Cyberpartisans. The group’s operations have centered on anti-regime and anti-war objectives rather than conventional financial gain. Publicly claimed activity includes attacks against Belarusian government entities, the Belarusian railway, and Russian organizations. Its railway operations were framed as efforts to hinder Russian troop movements through Belarus. Belarusian Cyber Partisans has also been linked in public reporting to a ransomware-style disruption of Belarusian Railway information systems in early 2022 in which the group reportedly demanded political concessions rather than payment. In 2025, the group and the pro-Ukraine actor Silent Crow claimed responsibility for a major attack on Aeroflot that caused widespread flight disruption and allegedly involved deep network penetration, destructive impact on enterprise IT, and data theft. Belarusian Cyber Partisans is best characterized as a politically motivated intrusion actor operating in the overlap between hacktivism, sabotage, and intelligence collection. Reported tradecraft associated with the group includes exploitation of public-facing services for initial access, credential theft, use of remote administration and tunneling utilities, network reconnaissance, lateral movement over remote desktop protocols, persistence through exposed remote access, data destruction, and exfiltration. The group has also used public messaging channels to amplify the political effect of its operations and to shape narratives around Belarusian and Russian state repression and the war in Ukraine. The actor has been described as pro-Ukraine and anti-Russian in orientation and has stated that information obtained from Russian targets was shared with Ukrainian intelligence services and Western organizations. Russia has sought to designate Belarusian Cyber Partisans as an extremist organization, reflecting the group’s sustained targeting of Russian and Belarusian state interests. While often labeled a hacktivist collective, its operations have shown a level of planning, persistence, and strategic messaging that places it among the more capable politically motivated cyber actors active in the Belarus-Ukraine-Russia conflict space. Known associated names in reporting include Silent Crow as a collaborator in at least one major operation. No verified sub-groups are clearly established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Included as contextual background on actors capable of targeting Russian infrastructure; not linked by evidence to the dairy-sector incidents in this report.
Hacktivist group that emerged after the 2020 Belarus protests and has conducted cyber operations against Belarusian state institutions, the Belarusian railway network, and Russian entities; it also claimed involvement in the 2025 Aeroflot attack and said it shared hacked information from Russian entities with Ukrainian intelligence services and Western organizations.
Referenced as an example hacktivist group in a framework discussing the hacktivism ecosystem and how such activity can be used to obscure intent and shape narratives.
Hacktivist group referenced in connection with an attack on Russian airline Aeroflot.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.