CyberHunta is a Ukrainian hacktivist group active in the context of the Russia-Ukraine conflict and best known for publishing a large archive of emails attributed to the office of Kremlin aide Vladislav Surkov. It is also referenced as part of the Ukrainian Cyber Alliance, a volunteer coalition that included CyberHunta, Falcons Flame, Trinity, and RUH8. The group’s operations have been framed as efforts to expose Russian state involvement in Crimea and eastern Ukraine and to support Ukrainian interests in the information domain. CyberHunta is most prominently associated with the compromise and release of more than 2,300 emails and attachments linked to Surkov’s office. Portions of that archive were assessed as authentic by multiple analysts and were partially corroborated by correspondents and Ukrainian authorities, although some documents in related releases were disputed and not all materials were conclusively validated. The leaked correspondence was widely interpreted as evidence of Kremlin coordination with pro-Russian separatists in eastern Ukraine, including political management, propaganda drafting, staffing recommendations, and support for separatist information structures. Reporting links CyberHunta and the broader Ukrainian Cyber Alliance to intrusions, data theft, website compromises, and information operations against Russian and separatist targets. Methods attributed to the alliance include spear-phishing, malware use, and other intrusion techniques; one account specifically credits CyberHunta with using malware or other specialized software in the Surkov compromise rather than spear-phishing. The alliance also reportedly hacked and defaced separatist-linked websites and targeted Russian government resources. CyberHunta therefore fits the profile of a politically motivated hacktivist actor focused on intelligence collection, exfiltration, and public disclosure in support of Ukraine during wartime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member group of the Ukrainian Cyber Alliance credited with the Surkov e-mail theft and broader compromise of Russian presidential administration systems.
Hacktivist-style intrusion and leak operation claiming to have hacked the email account of Vladislav Surkov's office and publicly released thousands of emails related to Kremlin involvement in eastern Ukraine.
Claimed responsibility for leaking thousands of emails reportedly stolen from Vladislav Surkov's inbox, in an operation framed around exposing Russian efforts to destabilize Ukraine.
A Ukrainian hacker group that claimed to have hacked Vladislav Surkov's e-mail account and published leaked e-mails and documents purportedly showing Russian coordination with separatists in eastern Ukraine and plans to destabilize Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.