Trinity is a pro-Ukrainian hacktivist group associated with the Ukrainian Cyber Alliance, a volunteer coalition that has included CyberHunta, Falcons Flame, RUH8, and Trinity. The group emerged in the context of the Russia-Ukraine conflict and has participated in operations intended to expose or disrupt Russian and pro-Russian actors. Trinity has been linked to website compromises and defacements targeting separatist entities in occupied Ukrainian territory and Russian-aligned infrastructure, including operations against websites associated with the self-proclaimed Donetsk People's Republic and Crimean targets. Trinity has also been publicly associated with the broader campaign around the compromise and release of materials attributed to Kremlin aide Vladislav Surkov, alongside other Ukrainian Cyber Alliance members. Reported tradecraft associated with the alliance that Trinity belongs to includes spear-phishing, malware-enabled compromise, encrypted operational coordination, data theft, and public disclosure of stolen information for political effect. Observed activity indicates capabilities spanning initial access, defacement and post-compromise operations, exfiltration, and influence-oriented information release. Trinity is best characterized as a hacktivist actor aligned with Ukrainian interests rather than a state organ, although its operations have focused heavily on Russian government-linked, separatist, and occupation-related targets during the conflict.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ukrainian hacktivist group within the Ukrainian Cyber Alliance involved in hacking and defacing separatist and Russian-linked websites.
Named as a hacker group working with CyberJunta in the Surkov document leak operation.
Participated in website compromise/defacement operations against Crimean and separatist websites, including posting political statements and messages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.