Server Killers, also known as ServerKillers, is a pro-Russian hacktivist group active since 2023 and aligned with the Russian hacktivist ecosystem. The group primarily conducts or claims volumetric distributed denial-of-service attacks against government-facing and public digital infrastructure, using politically framed messaging to amplify disruption and public concern. It has claimed campaigns against Norway in response to Norwegian support for Ukraine, including disruption of services operated by the Norwegian Digitalisation Agency. It has also claimed targeting in Denmark, the United Kingdom, Romania, Canada, Israel, and Italy. Server Killers has been associated with NoName057(16) based on operational and messaging similarities, but direct Russian state control has not been publicly established. The group has also participated in pro-Russian campaigns directed at Israeli judicial, educational, and governmental web infrastructure and has been identified as a potential threat to high-profile European events. Its activity is principally hacktivist and disruptive rather than ransomware-related.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pro-Russian group that claimed responsibility for a DDoS attack against Norwegian national digital public-services infrastructure. The content states that there is insufficient public evidence that it operated under direct Russian intelligence control.
Claimed responsibility for a series of DDoS attacks against Norwegian government digital infrastructure, reportedly in response to a Norway–Ukraine drone-defense agreement.
Claimed responsibility for DDoS attacks against infrastructure operated by Norway's Digitalisation Agency, disrupting multiple Norwegian government services. The group cited Norway's drone-defense agreement with Ukraine as its alleged motivation.
Claimed responsibility for an ongoing denial-of-service campaign against Norway's public digital-service agency, apparently in response to Norway renewing security cooperation with Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.