The White Pulse is a Russian-linked hacktivist threat group identified as a member of the Russian Legion alliance alongside Cardinal, Russian Partizan, and Inteid. The alliance emerged publicly in January 2026 and was associated with coercive cyber activity directed at Denmark in support of Russian geopolitical objectives related to Danish military aid for Ukraine. Within this coalition, The White Pulse is linked to coordinated disruptive operations and public threat messaging intended to pressure a foreign government and amplify psychological impact. The group is associated with operations centered on distributed denial-of-service activity against Danish companies and public-sector organizations, with repeated attention to the energy sector. The broader campaign combined service disruption with intimidation and information effects, including public ultimatums, claims of escalating attacks, and publication of evidence of disruption to magnify fear and media attention. Reporting assessed the alliance as likely state-aligned but not state-funded, consistent with Russian-linked hacktivist ecosystems that operate independently while advancing Kremlin-aligned narratives and objectives. Known activity attributed to the alliance involving The White Pulse indicates capabilities in disruptive operations, target selection tied to geopolitical events, and coordinated psychological pressure. High-confidence reporting supports DDoS-based disruption and public operational signaling; more advanced intrusion capabilities were threatened by the alliance but are not corroborated here as executed by The White Pulse specifically.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named member of the Russian Legion alliance threatening cyberattacks against Denmark.
Member group within the Russian Legion alliance participating in the coordinated “OpDenmark” DDoS pressure campaign against Denmark.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.