Skip to main content
Mallory
4 malware families

BO Team

Also known asBlack Owlbo_team

BO Team is a pro-Ukrainian hacktivist group, also known as Black Owl, Hoody Hyena, and Lifting Zmiy, that has been active since at least January or early 2024. The group targets Russian organizations and companies, including state-owned entities and sectors such as healthcare, manufacturing, telecommunications, oil and gas, logistics, internet service providers, scientific research, digital-signature services, and industrial environments. Reporting also describes attacks against Russian drone-related organizations and online services associated with Russia’s ruling party. BO Team has been publicly linked to cooperation with Ukraine’s military intelligence agency HUR/GUR in multiple operations, including attacks against a Russian scientific research center, online services of Russia’s ruling party, the federal digital-signature authority Osnovanie, logistics company Eltrans+, ISP Orion Telecom, and drone supplier Gaskar Group. BO Team has also been reported alongside the Ukrainian Cyber Alliance in destructive operations against Gaskar Group and other industrial environments. The group commonly gains initial access through targeted phishing emails with malicious attachments, including password-protected RAR archives and files disguised as legitimate documents. Kaspersky reported BO Team phishing campaigns tailored to Russian targets, including insurer- and bank-themed lures and decoy documents themed as internal investigations. BO Team has used living-off-the-land techniques and legitimate remote access tools, and has used RDP and SSH for lateral movement. Malware and tooling associated with BO Team in the provided content include BrockenDoor, ZeronetKit, Remcos, DarkGate, Babuk ransomware, Mythic, Cobalt Strike, HandleKatz, NanoDump, AnyDesk, and SDelete. BrockenDoor has been observed as a backdoor delivered via phishing, including a C#-rewritten version that checks for a Russian keyboard layout before execution. In at least one case, BrockenDoor downloaded and installed the Go-based ZeronetKit backdoor, which supports remote shell access, file transfer, and TCP tunneling. Reporting also states BO Team uses post-exploitation activity for sabotage, data theft, persistence, endpoint discovery, LSASS dumping, Active Directory database extraction, backup destruction, file deletion, and extortion. The content indicates BO Team initially emphasized destructive activity but later expanded toward more covert operations, including cyber espionage. Kaspersky reported that BO Team targeted 20 organizations in Q1 2026 and described it as a serious and continuously evolving threat in the Russian cyber threat landscape. Separate reporting described BO Team as a major threat to Russian state institutions and critical infrastructure. There is reporting that BO Team appears to be coordinating some operations with the group Head Mare against Russian organizations, based on overlapping infrastructure and tools and command-and-control systems observed on the same compromised host. Kaspersky said the exact nature of the BO Team–Head Mare relationship remains unclear, but suggested a possible division of labor in which Head Mare obtains initial access through phishing and BO Team conducts malware deployment and follow-on operations.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇷🇺 Russia
MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566×2
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
TA0003
Persistence
2 techniques
T1112
Modify Registry
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
1 technique
T1036
Masquerading
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0007
Discovery
1 technique
T1614
System Location Discovery
T1614.001
System Language Discovery
TA0009
Collection
1 technique
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1090
Proxy
T1105
Ingress Tool Transfer
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
TA0040
Impact
4 techniques
T1485×2
Data Destruction
T1491
Defacement
T1491.001
Internal Defacement
T1498
Network Denial of Service
T1498.001
Direct Network Flood
T1565
Data Manipulation
IOCS

Observables

42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables42

Domains, IPs, and hashes tied to this actor, refreshed continuously.