Digital Revolution is a Russian-language hacktivist intrusion group known for publicizing breaches of organizations linked to the Russian Federal Security Service (FSB) and its contractors. The group is publicly associated with the disclosure of stolen materials from FSB-connected entities including the Kvant research institute and SyTech. In the SyTech incident, Digital Revolution received exfiltrated data from another actor and then amplified the operation by publishing details and distributing leaked documents to journalists. Reporting around these disclosures tied the leaked materials to FSB-associated projects involving social-media collection, Tor deanonymization, peer-to-peer network research and infiltration, email monitoring, internet topology mapping, and protected government communications infrastructure. Digital Revolution’s activity is characterized by unauthorized access to sensitive networks or collaboration in the dissemination of stolen data, followed by public exposure of internal documents from Russian state-security contractors. The group’s operations indicate capabilities related to initial access, post-exploitation, exfiltration, and reconnaissance, with a dominant profile aligned to hacktivist exposure of Russian security-service cyber programs rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Received and further disclosed data stolen from SyTech and was previously reported to have breached Quantum, another FSB contractor, helping expose internal Russian intelligence contractor projects.
Хактивистская группа, получившая и передавшая журналистам документы, похищенные после взлома подрядчика российских спецслужб; ранее брала на себя ответственность за взлом сервера НИИ «Квант».
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.