KillNet 2.0 is a decentralized international hacktivist collective that emerged from the fragmentation and rebranding of the original KillNet ecosystem. It is associated with the broader pro-Russia hacktivist milieu and has positioned itself as a more globally distributed organization focused on targeted cyber operations. Reporting indicates the original KillNet structure split into multiple factions, including Deanon, KillNet 2.0, and Just Evil, with KillNet 2.0 serving as the branch oriented toward recruiting international participants and expanding decentralized operations. The group is linked to politically motivated cyber activity aligned with Russian geopolitical narratives. It has been associated with campaigns against Israel and countries or institutions perceived as supporting Israel, Ukraine, or NATO. KillNet and its successor branding became widely known for disruptive distributed denial-of-service operations against government and public-facing targets during and after the 2022 Russian invasion of Ukraine. KillNet 2.0 has also been described as emphasizing more targeted intrusions and compromise of sensitive information rather than relying solely on volumetric disruption. Known activity attributed to KillNet 2.0 includes claimed attacks against Israeli government and security-related websites, public declarations of continued operations against Israeli state systems, and collaboration or alignment with other Russian-associated and pro-Palestinian hacktivist entities. Its operational profile therefore spans disruptive attacks, politically themed targeting, and intrusion-oriented actions intended to demonstrate capability, exert pressure, and amplify geopolitical messaging. Aliases and related entities include KillNet 2.0, the original KillNet brand, Deanon, and Just Evil. The actor is best characterized as a hacktivist threat group with influence-oriented and disruptive objectives rather than a financially motivated criminal enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.