22c is a threat group observed among the set of actors participating in cyber operations targeting Ukraine. It has been identified in the broader ecosystem of groups contributing to the hostile cyber landscape affecting Ukrainian entities, particularly alongside other pro-Russian or anti-Ukrainian hacktivist actors. Available high-confidence reporting places the group in campaigns affecting Ukraine during a period marked by heavy disruptive activity, especially against government and other nationally significant targets. The surrounding campaign environment was dominated by distributed denial-of-service activity, website defacement, and data-breach activity, with government entities as the most heavily targeted sector and additional pressure on technology, transportation, energy, media, and education organizations. Specific tactics, victimology, operational tradecraft, and attribution details unique to 22c are currently not available at high confidence beyond its inclusion among the actors active in this threat landscape.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.