Pro-Russia Hacktivists is a collective label used in the provided reporting for pro-Russian hacktivist activity targeting critical infrastructure in the United States and allied countries. According to joint advisories from CISA, FBI, DC3, the Canadian Centre for Cyber Security, Europol, and other European agencies, these actors conduct primarily opportunistic and unsophisticated attacks focused on operational disruption, with potential for physical damage. Reported targeting includes water and wastewater, food and agriculture, energy, healthcare, public health, and other critical infrastructure sectors, with risk extending to operational technology environments. The activity described relies on exploitation of known unpatched vulnerabilities in Internet-facing systems, especially minimally secured VNC connections, desktop-sharing systems, and unsecured VNC human-machine interfaces (HMIs) to obtain unauthorized access. Campaigns may also be accompanied by DDoS activity, and the actors are reported to publicize, exaggerate, or fabricate claims about their attacks for visibility. No specific sub-groups are identified in the provided content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russia hacktivist groups are conducting opportunistic cyberattacks against US and global critical infrastructure, likely as part of information warfare and disruption campaigns.
Pro-Russia hacktivists are targeting critical infrastructure by exploiting unsecured VNC Human-Machine Interfaces (HMIs), likely to disrupt operations or cause damage.
Pro-Russia hacktivist groups are conducting unsophisticated, opportunistic cyberattacks against critical infrastructure entities in countries perceived as adversaries of Russia. Their primary aim is to disrupt operations, potentially causing physical damage, and to amplify their activities for visibility, sometimes fabricating claims of attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.