BO Team is a pro-Ukrainian hacktivist group active since at least early 2024 and also known as Black Owl, Hoody Hyena, and Lifting Zmiy. It primarily targets Russian organizations, including state institutions, defense-related entities, telecommunications providers, manufacturing companies, healthcare organizations, and oil and gas firms; Belarusian targets have also been reported. The group has publicly collaborated with Ukraine's military intelligence directorate, HUR, in operations against Russian infrastructure and defense-related organizations, although its operational relationship to Ukrainian state services is not established as direct command or control. BO Team conducts targeted phishing campaigns, commonly using malicious attachments disguised as legitimate business documents, including password-protected archives and decoy files. It has used BrockenDoor and ZeronetKit backdoors, as well as commodity malware such as DarkGate and Remcos, to establish remote access, execute commands, transfer files, and tunnel network traffic. Reported post-compromise activity includes persistence, endpoint and Active Directory data collection, LSASS credential dumping, use of Cobalt Strike and Mythic, deployment of legitimate remote-access software, and lateral movement using RDP and SSH. The group has conducted destructive operations involving data and backup deletion and has used Babuk ransomware for extortion. Its activity has evolved from overtly destructive operations toward more covert access, collection, and espionage-oriented operations. Infrastructure and tooling overlap indicates at least some coordination with the Ukraine-aligned Head Mare group, potentially with Head Mare providing phishing-based initial access and BO Team conducting follow-on activity; the precise nature of that relationship remains unresolved.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously associated with a closely similar malicious network-provider infection chain that was later observed, in modified form, in a Hacking Cat-linked destructive incident.
Hybrid group combining extortion and destructive operations across a broad target set.
Cited as an example of a Ukraine-aligned group active against Russian targets; no evidence in the content links it to the dairy-sector incidents analyzed here.
Pro-Ukraine hacktivist group conducting attacks against Russian organizations, increasingly shifting from destructive activity to covert cyber espionage and coordinating at least partially with Head Mare.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.