0v1ru$ is a hacker group publicly associated with the July 2019 breach of SyTech, a Moscow-based contractor linked to the Russian FSB. The group reportedly compromised SyTech’s Active Directory environment, gained broad access across the company’s internal network including a JIRA instance, stole approximately 7.5 terabytes of data, and defaced the victim’s website. Material taken in the intrusion was subsequently shared with the hacktivist group Digital Revolution, which helped publicize the leak. The operation exposed internal documents describing multiple non-public projects developed for Russian security and government customers, including work tied to military unit 71330 and other state-linked entities. Reported projects included capabilities for social media collection, Tor deanonymization, peer-to-peer network infiltration research, email monitoring, internet topology mapping, and protected communications infrastructure. Public reporting around the incident framed the breach as a significant exposure of Russian intelligence-related cyber programs. Based on the available facts, 0v1ru$ demonstrated capabilities spanning initial access, post-exploitation, privilege over enterprise infrastructure, internal reconnaissance, data exfiltration, and disruptive website defacement. The actor’s known activity in this case was directed at a Russian intelligence contractor, and the public release pathway through Digital Revolution is consistent with an anti-establishment or hacktivist posture. No high-confidence evidence in the available material supports broader attribution, state sponsorship, or a larger sustained campaign beyond this intrusion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Breached SyTech, an FSB contractor, stole 7.5TB of data, accessed the company's broader network via Active Directory compromise, defaced the website, and exposed internal FSB-related project information.
Группа, связанная со взломом и дефейсом сайта «Сайтэк», публикацией скриншотов внутренней сети и удалением/эксфильтрацией данных подрядчика российских спецслужб.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.