Anonymous Poland is a false hacktivist persona used in information operations associated with the public leaking of stolen data. It has been identified alongside other personas such as Guccifer 2.0, DC Leaks, CyberCaliphate, and Fancy Bears’ Hack Team in campaigns linked by security researchers to APT28, a Russian state-aligned threat actor widely tracked as Fancy Bear. The persona fits a broader pattern in which intrusions against political, governmental, military, media, and sports-related targets were followed by strategic disclosure of stolen material to shape narratives and support Russian active measures. The underlying operations associated with this persona are tied to espionage-oriented collection and post-compromise information release rather than conventional ransomware activity. Reported tradecraft in the broader APT28-linked campaigns included spearphishing, credential theft through fraudulent OAuth authorization workflows designed to bypass two-factor authentication, use of zero-day exploits, reliance on public offensive tooling, and lateral movement using legitimate administrative tools already present in victim environments. Although collection activity was linked to APT28, public reporting noted that direct control of individual leak personas was not always conclusively established. Anonymous Poland is therefore best understood as a deceptive influence and leak brand within the APT28 ecosystem rather than a standalone intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.