FalconsFlame is a pro-Ukrainian hacktivist group associated with the Ukrainian Cyber Alliance, a volunteer coalition that has included CyberHunta, Trinity, and RUH8. The group emerged in the context of the Russia-Ukraine conflict and has been linked to operations intended to expose, disrupt, and embarrass Russian state, separatist, and occupation-linked entities. FalconsFlame has been publicly associated with campaigns against targets tied to the self-proclaimed Donetsk People’s Republic, Crimea under Russian control, and Russian interests connected to the war in Ukraine. FalconsFlame has been tied to website compromises and defacements of separatist and Crimean sites, including coordinated operations with Trinity and CyberHunta. The group was also named as a partner in the broader campaign surrounding the compromise and publication of materials attributed to Kremlin aide Vladislav Surkov, an operation framed by allied actors as exposing Russian coordination with separatists and destabilization efforts against Ukraine. Reporting on the wider coalition indicates use of spear-phishing, malware, and other intrusion methods, although attribution of specific access methods to FalconsFlame individually is not always separated from the alliance as a whole. The group’s activity is consistent with hacktivism rather than financially motivated cybercrime. Its known operations have emphasized intrusion, defacement, information theft, and public release of politically sensitive material in support of Ukrainian interests during the conflict with Russia and Russian-backed separatists.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ukrainian hacktivist group within the Ukrainian Cyber Alliance involved in hacking and defacing separatist and Russian-linked websites.
Named as a hacker group working with CyberJunta in the Surkov document leak operation.
Conducted website compromise/defacement operations against Crimean and separatist websites, posting political messages and statements tied to commemorative and geopolitical themes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.