Rainbow Hyena is a Ukrainian-aligned hacktivist intrusion set associated with phishing-led operations against Russian organizations, including the aerospace sector and entities supporting Russia’s military effort. Reported aliases include Fairy Trickster, Head Mare, and PhantomCore, and the activity has been assessed to overlap with Hive0117 and Operation CargoTalon. Observed operations between June and September 2025 targeted the Russian aerospace industry and other Russian business functions such as finance, accounting, procurement, legal, human resources, and payroll. The actor’s tradecraft centers on spear-phishing and credential theft. Campaigns have used payment-confirmation and policy-themed lures, malicious archive attachments, shortcut-based download chains, and phishing pages impersonating enterprise login portals. Associated malware and tooling observed in related activity include Phantom Stealer, DUPERUNNER, AdaptixC2, Cobalt Strike, Formbook, DarkWatchman, and PhantomRemote. Capabilities documented across this activity include theft of browser credentials and cookies, Discord tokens, payment-card data, cryptocurrency wallet data, clipboard monitoring, keylogging, anti-analysis checks for sandbox or virtualized environments, process injection, and data exfiltration through common attacker-controlled channels. The actor has also used compromised email infrastructure to distribute spear-phishing messages and has pursued post-compromise access against organizations cooperating with Russia’s armed forces. The cluster is best characterized as a politically aligned anti-Russian threat actor conducting intrusion and information-stealing operations rather than ransomware or destructive attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.