Narodnaya Cyber Army, also referred to as The People’s Cyber Army and stylized as @NarodnayaCyberArmiya, is a pro-Russian hacktivist entity involved in disruptive cyber operations aligned with geopolitical narratives surrounding the Russia-Ukraine war. The group has been observed participating in coordinated campaigns alongside other Russian-speaking hacktivist actors, particularly NoName057(16), and has taken part in attacks against United Kingdom organizations. Its activity is characterized primarily by distributed denial-of-service operations against public-facing targets. The group appears to operate in a rapid-response model common to contemporary hacktivist ecosystems, reacting quickly to major political developments and amplifying operations through Telegram-based coordination and publicity. Reported targeting has focused on high-visibility organizations and sectors associated with national infrastructure and public life, including energy, transportation, financial services, non-governmental organizations, and broader critical infrastructure. The actor’s operations are consistent with disruptive hacktivism intended to generate publicity, signal political alignment, and impose short-term service disruption rather than achieve covert persistence or long-term network compromise. Narodnaya Cyber Army has been documented joining broader pro-Russian attack waves against the United Kingdom, including activity around the 2024 UK general election, where it acted in coordination with NoName057(16) and other aligned groups. Available evidence supports classification as a hacktivist actor with politically driven disruptive operations rather than a ransomware or espionage-focused intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.