Server Killers
Server Killers is a Russian-linked, pro-Kremlin hacktivist group active in disruptive campaigns aligned with Russian and anti-Western interests. The group is identified in reporting as one of several pro-Russia hacktivist actors posing a viable threat to the 2024 Paris Summer Olympics, alongside Anonymous Sudan, Cyber Army of Russia Reborn, NoName057(16), and UserSec. It was also listed among pro-Kremlin hacktivist groups targeting Olympics-related entities during the Milano Cortina 2026 Winter Games period, where it accounted for 8 public attack claims. The group has publicly aligned itself with anti-Israel operations. Reporting states that a Telegram channel presumably operated by Russian-speaking actors announced that Server Killers was joining the cyber war against the United States and Israel, citing the U.S.-Israel strikes as justification. In that context, Server Killers was described as initiating attacks against Israeli judicial, educational, and governmental web infrastructure. Additional reporting notes that the group re-engaged in the broader anti-Israel campaign while other aligned actors targeted European infrastructure. Based on the provided content, Server Killers is associated primarily with disruptive hacktivist activity, especially publicly claimed DDoS-style operations against high-profile government and public-sector web infrastructure. The content does not provide verified evidence of more advanced intrusion capabilities. Known alias in the provided material: server_killers.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor publicly claiming DDoS-related attacks against Italian targets during the Winter Games period.
Pro-Russian-aligned group that entered the pro-Iran cyber coalition during the 2026 escalation.
Opportunistic group joining anti-US and anti-Israel cyber activity, with exaggerated claims of support to Iran.
Russian-linked entrant publicly joining the conflict on the pro-Iran side, though no concrete operations are detailed in the content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.