Russian Partizan is a Russian hacktivist threat group identified as a member of the Russian Legion alliance alongside Cardinal, The White Pulse, and Inteid. The alliance emerged publicly in January 2026 and conducted a coordinated campaign branded as OpDenmark, threatening and then carrying out disruptive cyber activity against Denmark in response to Danish military aid to Ukraine. Russian Legion was assessed as state-aligned but not state-funded, operating in support of Russian geopolitical objectives while remaining outside formal state structures. Russian Partizan is associated through this alliance with disruptive operations centered on distributed denial-of-service activity, public coercive messaging, and psychological operations. The campaign against Denmark combined ultimatum-style threats, public claims of attacks against Danish companies and public organizations, and amplification through screenshots and messaging on Telegram to increase fear, uncertainty, and political pressure. Repeated references to Denmark’s energy sector indicate particular interest in critical infrastructure and public-impact targets. The alliance also threatened escalation beyond DDoS into broader cyberattacks if its political demands were not met. Based on the available facts, Russian Partizan should be understood as part of a pro-Russian hacktivist ecosystem that uses disruptive cyber operations, intimidation, and influence-oriented messaging in support of Russian strategic narratives. Known associated grouping: Russian Legion. Known alliance members: Cardinal, The White Pulse, Inteid, and Russian Partizan.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named member of the Russian Legion alliance threatening cyberattacks against Denmark.
Member group within the Russian Legion alliance participating in the coordinated “OpDenmark” DDoS pressure campaign against Denmark.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.