BO Team
BO Team is a pro-Ukrainian hacktivist group, also known as Black Owl, Hoody Hyena, and Lifting Zmiy, that has been active since at least January or early 2024. The group targets Russian organizations and companies, including state-owned entities and sectors such as healthcare, manufacturing, telecommunications, oil and gas, logistics, internet service providers, scientific research, digital-signature services, and industrial environments. Reporting also describes attacks against Russian drone-related organizations and online services associated with Russia’s ruling party. BO Team has been publicly linked to cooperation with Ukraine’s military intelligence agency HUR/GUR in multiple operations, including attacks against a Russian scientific research center, online services of Russia’s ruling party, the federal digital-signature authority Osnovanie, logistics company Eltrans+, ISP Orion Telecom, and drone supplier Gaskar Group. BO Team has also been reported alongside the Ukrainian Cyber Alliance in destructive operations against Gaskar Group and other industrial environments. The group commonly gains initial access through targeted phishing emails with malicious attachments, including password-protected RAR archives and files disguised as legitimate documents. Kaspersky reported BO Team phishing campaigns tailored to Russian targets, including insurer- and bank-themed lures and decoy documents themed as internal investigations. BO Team has used living-off-the-land techniques and legitimate remote access tools, and has used RDP and SSH for lateral movement. Malware and tooling associated with BO Team in the provided content include BrockenDoor, ZeronetKit, Remcos, DarkGate, Babuk ransomware, Mythic, Cobalt Strike, HandleKatz, NanoDump, AnyDesk, and SDelete. BrockenDoor has been observed as a backdoor delivered via phishing, including a C#-rewritten version that checks for a Russian keyboard layout before execution. In at least one case, BrockenDoor downloaded and installed the Go-based ZeronetKit backdoor, which supports remote shell access, file transfer, and TCP tunneling. Reporting also states BO Team uses post-exploitation activity for sabotage, data theft, persistence, endpoint discovery, LSASS dumping, Active Directory database extraction, backup destruction, file deletion, and extortion. The content indicates BO Team initially emphasized destructive activity but later expanded toward more covert operations, including cyber espionage. Kaspersky reported that BO Team targeted 20 organizations in Q1 2026 and described it as a serious and continuously evolving threat in the Russian cyber threat landscape. Separate reporting described BO Team as a major threat to Russian state institutions and critical infrastructure. There is reporting that BO Team appears to be coordinating some operations with the group Head Mare against Russian organizations, based on overlapping infrastructure and tools and command-and-control systems observed on the same compromised host. Kaspersky said the exact nature of the BO Team–Head Mare relationship remains unclear, but suggested a possible division of labor in which Head Mare obtains initial access through phishing and BO Team conducts malware deployment and follow-on operations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Observables
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Ukraine hacktivist group conducting attacks against Russian organizations, increasingly shifting from destructive activity to covert cyber espionage and coordinating at least partially with Head Mare.
Group reported as conducting operations against industrial environments.
Hacktivist operations, including wiping the networks of Russian ISPs SimStar and Kraft-S.
Pro-Ukraine hacktivist group claimed participation (with Ukraine GUR) in destructive attacks against Russian logistics infrastructure, including server wiping/data destruction.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.