Russian Business Network (RBN) was a Russia-based organized cybercriminal group and bulletproof-hosting provider that became prominent in the mid-2000s as a major enabler of malicious online activity. By 2007 it was widely described as one of the largest providers of criminal internet infrastructure in Russia, supporting operations including phishing, identity theft, malware distribution, fraud, spam, botnet command-and-control, and distributed denial-of-service attacks. RBN has also been associated in reporting with other serious criminal enterprises, including illicit content distribution. RBN is best known for providing resilient hosting and network services to abusive customers and for its links to botnet-driven operations. Its infrastructure and tooling were repeatedly tied by researchers to spam campaigns, botnet activity, and DDoS operations. Historical reporting also connected RBN to major politically salient DDoS campaigns, including the 2007 attacks on Estonia, the 2008 cyberattacks on Georgia, and the 2009 attacks on Kyrgyzstan, although the degree of direct state coordination in those cases remained unclear. In the Georgia case, researchers reported overlap between attack tools, commands, and systems previously associated with RBN, as well as evidence that botnets linked to the group were staged before hostilities and activated as the conflict escalated. RBN exemplified the overlap between organized cybercrime and geopolitically relevant cyber operations in the Russian ecosystem. It has been characterized as a St. Petersburg-based criminal gang with ties to spamming, botnets, pharmaceutical affiliate schemes, phishing, and credential-focused fraud. Reporting has also described its presence or operations under other names and noted its association with broader Russian organized crime. The dominant motivation associated with RBN is financial gain, even though some activity linked to its infrastructure intersected with coercive or politically consequential campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted or was believed to conduct coordinated DDoS campaigns aligned with Russian geopolitical objectives, including attacks on Estonia, Georgia, and Kyrgyzstan using botnet-driven disruption.
Criminal infrastructure provider in Russia supporting phishing, identity theft, malware distribution, fraud, botnet C2, and DDoS activity.
Described as a Russian organized crime-linked cybercrime group hosted in the UK and associated with broader cybercrime activity and infrastructure use.
Named as a criminal enterprise client associated with McColo's bulletproof hosting environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.