256th Cyber Assault Division is a self-described Ukrainian hacker group that has publicly claimed operations against Russian military personnel involved in unauthorized use of satellite communications equipment in the Russia-Ukraine war. The group said it impersonated a service capable of restoring disconnected terminals, inducing Russian servicemen to submit identifying information and location-related data and to transfer money under false pretenses. It further claimed that the collected information was passed to Ukrainian law enforcement and defense bodies and that funds obtained would support Ukrainian drone fundraising. The reported activity indicates use of spoofing and reconnaissance in support of wartime counter-operations against Russian forces. Attribution details, organizational structure, and the full extent of the group’s operations remain unverified in publicly available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.