Punishing Owl is a hacktivist threat actor that emerged in late 2025 and has conducted politically motivated intrusions against Russian organizations, including government security agencies, state institutions, scientific enterprises, IT organizations, and broader critical infrastructure-related targets. The group is known for combining data theft, public leaking, and follow-on abuse of compromised communications infrastructure to amplify operational and psychological impact. Punishing Owl has used phishing emails carrying password-protected ZIP archives that contain Windows shortcut files disguised as documents. Execution of the shortcut triggers PowerShell to retrieve and run a stealer known as ZipWhisper. ZipWhisper has been used to collect browser credentials, cookies, saved passwords, and other sensitive data, package the stolen material, and exfiltrate it to attacker-controlled infrastructure. The actor has also established persistence and operational support infrastructure for email-based abuse, including use of SMTP and IMAP services and fake TLS certificates. In at least one notable operation, Punishing Owl compromised a Russian government security agency, stole internal documents, and publicly leaked them. The actor also manipulated the victim’s DNS configuration to redirect traffic to attacker-controlled infrastructure hosting stolen files and a political manifesto, indicating both technical sophistication and an intent to maximize public visibility. After the initial breach, the group expanded activity into business email compromise against the victim’s partners and contractors by sending messages from addresses created within the compromised victim domain. This demonstrates capability beyond simple intrusion and theft, extending into post-compromise impersonation and secondary targeting. The actor is assessed as politically motivated and aligned with hacktivist objectives rather than financially driven cybercrime. One known social media account associated with the group has been administered from Kazakhstan. No additional aliases or formally identified sub-groups are currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Politically motivated (suspected hacktivist) actor targeting Russian state/scientific/IT organizations; steals and leaks data; uses phishing with password-protected ZIPs delivering LNK that runs PowerShell to install a stealer (ZipWhisper) for data exfiltration.
Politically motivated (suspected hacktivist) actor targeting Russian entities; uses phishing with password-protected ZIPs containing LNK masquerading as PDFs to execute PowerShell that downloads the ZipWhisper stealer; steals and leaks data on dark web.
Newly emerged hacktivist group conducting intrusions and data leaks against Russian government security agencies, including DNS tampering to redirect traffic to attacker-controlled infrastructure, followed by business email compromise against partners/contractors and credential theft via a PowerShell-based stealer delivered through password-protected ZIPs containing LNK files.
Hacking and leaking data from Russian companies; operating via dark web leak activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.