BO Team, also known as Black Owl and reported under additional aliases including Hoody Hyena and Lifting Zmiy, is a pro-Ukraine hacktivist threat actor active since at least early 2024. The group primarily targets Russian organizations, including state institutions, telecommunications providers, industrial enterprises, oil and gas companies, healthcare entities, logistics firms, digital-signature service providers, scientific organizations, and companies connected to Russia’s defense and drone-production ecosystem. BO Team has also been reported targeting Belarusian organizations. The group is notable for combining politically motivated disruption with espionage, data theft, extortion, and destructive operations. Reporting indicates BO Team conducted dozens of attacks in 2025 and has paired ransomware-style pressure with sabotage and data destruction. It has been publicly associated with operations that disrupted Russian business processes, wiped servers and virtual infrastructure, destroyed or exfiltrated large data volumes, and impaired internet-facing and internal services. BO Team commonly gains initial access through targeted phishing emails carrying malicious attachments disguised as legitimate documents. The group has used password-protected archives, tailored social-engineering themes, and decoy documents customized to specific Russian-sector targets. Observed malware and tooling associated with BO Team include BrockenDoor, ZeronetKit, Remcos, DarkGate, Babuk ransomware, Cobalt Strike, Mythic, and legitimate remote administration utilities. Post-compromise activity has included living-off-the-land techniques, credential access, persistence establishment, lateral movement over remote administration channels, Active Directory data collection, backup destruction, and file deletion. BrockenDoor and ZeronetKit are particularly associated with the group’s phishing-led intrusions. BrockenDoor has been used as a backdoor and loader, including in a later C#-rewritten form, while the Go-based ZeronetKit backdoor has provided remote shell access, file transfer, and tunneling capabilities. BO Team has also been observed using commodity malware alongside custom or adapted tooling, reflecting an evolution from overtly destructive activity toward more covert and sustained intrusions, including cyber-espionage-oriented operations. BO Team has been described as more autonomous than many other pro-Ukraine hacktivist actors, but it has also been publicly linked to cooperation with Ukraine’s military intelligence service, HUR/GUR, in operations against Russian targets. Claimed or reported joint activity has included attacks on Russian scientific and administrative entities, digital-signature infrastructure, telecommunications and internet providers, logistics organizations, and drone-related companies. The group has also been linked to cooperation with the Ukrainian Cyber Alliance in destructive campaigns against Russian defense-sector targets. Research published in 2026 indicated apparent coordination between BO Team and Head Mare, based on overlapping infrastructure and tooling. One assessed model of cooperation suggested Head Mare may obtain initial access through phishing while BO Team conducts malware deployment and follow-on intrusion activity. The exact nature of that relationship remains unclear, but the overlap indicates at least some operational coordination in campaigns against Russian organizations. BO Team represents a significant actor in the Russia-Ukraine cyber conflict because it bridges hacktivist branding with intrusion tradecraft more typical of mature offensive operators. Its operations have spanned disruptive website and service attacks, destructive network intrusions, ransomware-enabled coercion, and intelligence collection against Russian governmental, commercial, and industrial targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hybrid group combining extortion and destructive operations across a broad target set.
Cited as an example of a Ukraine-aligned group active against Russian targets; no evidence in the content links it to the dairy-sector incidents analyzed here.
Pro-Ukraine hacktivist group conducting attacks against Russian organizations, increasingly shifting from destructive activity to covert cyber espionage and coordinating at least partially with Head Mare.
Group reported as conducting operations against industrial environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.