Wagner Group is a Russia-aligned private military and mercenary organization long associated with Yevgeny Prigozhin and widely assessed to have operated in close coordination with the Russian state despite formal denials and legal ambiguity around mercenary activity in Russia. It has been used as an instrument of Russian power projection, plausible deniability, coercion, and influence operations across multiple theaters, including Ukraine, Syria, Libya, and several African states, especially in the Sahel. In Africa, Wagner supported authoritarian and junta-led governments through combat operations, regime protection, training, disinformation, and resource-linked security arrangements; in Mali and neighboring states, its presence has been tied to counterinsurgency operations marked by widespread allegations of torture, rape, forced disappearances, extrajudicial killings, and other abuses against civilians. Following Prigozhin’s death and broader Russian state restructuring, parts of Wagner’s African role were reportedly absorbed into the Russian Ministry of Defense-backed Africa Corps, though the intervention model is widely assessed to have continued in similar form. In Ukraine, Wagner played a prominent combat role in the Donbas and became especially associated with highly attritional infantry tactics, including the expendable use of assault personnel in support of Russian fires. Wagner personnel were also reported in covert and decapitation-oriented activity during the opening phase of Russia’s full-scale invasion, including alleged efforts targeting senior Ukrainian leadership in Kyiv. The group has also been linked to operations in Syria and Libya, where it supported Russian-aligned forces and advanced Moscow’s geopolitical objectives while preserving a degree of deniability. Wagner is notable not only for expeditionary combat operations but also for hybrid activity spanning sabotage, recruitment, propaganda, and influence operations. Reporting has tied Wagner or Wagner-linked networks to disinformation campaigns in Africa, recruitment pipelines for sabotage and proxy operations in Europe, and support to Russian intelligence objectives. The organization has been associated with the use of Telegram and other online platforms for psychological operations and the dissemination of graphic violent content intended to intimidate adversaries and civilian populations. Wagner-linked ecosystems have also intersected with extremist and criminal financing activity, including cryptocurrency fundraising and, in the case of the Wagner-associated subunit Task Force Rusich, alleged malware-enabled theft and other illicit digital revenue generation. The group has repeatedly been accused of serious violations of international humanitarian law and human rights law. Allegations include torture and murder of prisoners, execution of civilians and captured combatants, mutilation and degrading treatment of the dead, and public advocacy or dissemination of no-quarter violence. Wagner-affiliated channels and former members have been cited in connection with atrocities in Ukraine, Syria, and Mali. These patterns have made Wagner one of the most notorious contemporary Russian proxy forces. Known aliases include Wagner and Wagner Group. Known associated or subordinate elements include Task Force Rusich, a far-right sabotage and assault reconnaissance formation that has operated alongside Wagner in Ukraine and Syria. Wagner’s significance lies in its role as a deniable but strategically aligned arm of Russian state power, combining mercenary warfare, coercive influence, irregular operations, and information warfare in support of Moscow’s foreign policy objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the source of tactics Russia adopted for infantry operations in Ukraine, specifically expendable infantry plus fires/UAV-heavy attritional assaults.
Referenced as a paramilitary organization whose mercenaries are considered desirable recruits for more professional Russian sabotage cells operating in Europe.
Referenced as the foreign group on whose behalf an arson campaign in the UK was masterminded.
Conducted disinformation operations and provided mercenary military support to Sahelian juntas, especially in Mali, while being associated with brutal counterinsurgency operations and human rights abuses.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.