The IT Army of Ukraine is a volunteer hacktivist collective formed shortly after Russia’s full-scale invasion of Ukraine in February 2022 following a public call by Ukraine’s Minister of Digital Transformation. Organized primarily through a Telegram channel, the group reportedly grew to roughly 200,000 volunteers and has conducted cyber operations in support of Ukraine against Russian targets. It is widely characterized as a pro-Ukraine hacktivist movement rather than a conventional state military unit, although its activities have aligned with Ukrainian wartime objectives and proposed legislation has sought to formalize its status within a reserve cyber component. The group has focused on Russian government-linked, transportation, commercial, and infrastructure-related targets. Publicly attributed activity includes distributed denial-of-service operations that disrupted Russian services, as well as broader disruptive and data-exposure operations claimed against organizations serving Ukrainian government and commercial customers. Reported actions also include using open-source data and facial recognition workflows to identify Russian military casualties and contact relatives, as well as publishing personal data related to Russian military personnel. Operationally, the IT Army is associated with disruptive cyber activity, especially DDoS campaigns, and with data theft and public disclosure claims in some incidents. Reported effects have included service outages, operational disruption, encryption of victim systems in at least one claimed incident, and exfiltration of sensitive information. At the same time, legal and analytical assessments have described the collective as decentralized and insufficiently hierarchical to clearly qualify as an organized armed group under international humanitarian law absent formal incorporation into Ukraine’s armed forces. Known reporting and self-attribution tie the IT Army of Ukraine to cyber operations against Russian aviation-related services and other Russian entities during the Russia-Ukraine war. The actor’s dominant motivation is political and wartime disruption in support of Ukraine rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for a distributed denial-of-service attack against Leonardo that disrupted operations for several Russian airlines and caused airport departure delays.
A volunteer cyber force aligned with Ukraine that has conducted cyber operations against Russian companies, infrastructure, and military-related targets during the Russia-Ukraine war. The content focuses on its legal status under the law of armed conflict and notes activities including website disruption, defacement, defensive cyber actions, and doxing of Russian military personnel.
Claims responsibility for hacking and encrypting 28 SoftPro.ua servers and exfiltrating approximately 102 GB of confidential data from a Ukrainian software developer serving government and commercial customers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.