Atesh is a pro-Ukraine partisan and resistance movement active in Russian-occupied areas of Ukraine, including Crimea, and reportedly composed in part of Ukrainians and Crimean Tatars. It is associated with the broader Ukrainian resistance ecosystem and has been described as operating in support of Ukraine’s war effort against Russian occupation forces. Publicly attributed activity includes sabotage of railway infrastructure and other logistics-related targets used to sustain Russian military operations, as well as reporting on Russian troop movements and occupation practices. Atesh has been linked to operations intended to disrupt Russian military logistics in occupied southern Ukraine and Crimea, including attacks on rail infrastructure supporting troop and materiel transport. Reporting also attributes to the group actions against infrastructure inside Russia connected to defense production and military supply chains. Its operational profile aligns with clandestine resistance activity focused on reconnaissance, intelligence support, sabotage, and disruption of occupation administration and rear-area sustainment. The group’s targets and messaging indicate a primary focus on Russian military and occupation structures rather than criminal monetization. Atesh is part of the wider pattern of Ukrainian resistance activity that includes covert intelligence collection, infrastructure sabotage, and support to Ukrainian special operations objectives in occupied territory. No high-confidence evidence in the supplied facts indicates ransomware or financially motivated cyber-extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reporting on Russian military logistics movements in Crimea, including tanker truck activity and concealment near civilian structures.
A Ukrainian resistance group used for sabotage operations in Crimea and other occupied areas.
A pro-Ukraine partisan resistance movement conducting sabotage and disruption operations against Russian military logistics and infrastructure in occupied Ukraine and inside Russia, including rail disruption and industrial sabotage.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.