Server Killers is a pro-Russian hacktivist group aligned with the broader Russian-speaking hacktivist ecosystem and primarily associated with volumetric distributed denial-of-service operations. The group has been identified alongside other pro-Kremlin collectives as a viable disruptive threat to high-profile international events and politically salient targets. It has participated in coordinated pile-on campaigns in which smaller aligned actors amplify operations designated by larger collectives, indicating an ecosystem role centered on opportunistic disruption rather than uniquely sophisticated intrusion tradecraft. The group has been linked to anti-Western and anti-Israel campaigns and has publicly framed some of its activity in geopolitical terms, including joining cyber operations against the United States and Israel. Reported targeting has included Israeli judicial, educational, and governmental web infrastructure, as well as broader European entities in the context of pro-Russian hacktivist mobilization. During periods of heightened geopolitical tension, Server Killers has appeared in the same operational milieu as groups such as NoName057(16), Cyber Army of Russia Reborn, Anonymous Sudan, UserSec, BD Anonymous, Dark Storm Team, and Z-Pentest Alliance. Server Killers is best characterized as a disruptive propaganda-oriented actor whose core capability is denial-of-service activity used for signaling, intimidation, and symbolic retaliation. Available reporting supports alignment with the Russian hacktivist ecosystem and Russian-speaking operators, but does not establish advanced intrusion, ransomware, or espionage capabilities at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-aligned volumetric DDoS group participating in coordinated pile-on campaigns against government, financial, and EU-linked targets.
Threat actor publicly claiming DDoS-related attacks against Italian targets during the Winter Games period.
Pro-Russian-aligned group that entered the pro-Iran cyber coalition during the 2026 escalation.
Opportunistic group joining anti-US and anti-Israel cyber activity, with exaggerated claims of support to Iran.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.