CyberJunta is a Ukrainian hacktivist group known for leaking materials allegedly stolen from Vladislav Surkov, a senior Kremlin aide closely associated with Russia’s Ukraine policy. The group publicly released purported email correspondence, personal document scans, and political planning documents that were presented as evidence of Kremlin coordination with separatist and nationalist actors and efforts to destabilize Ukraine. CyberJunta also stated that it was working with FalconsFlame, RUH8, and Trinity. Publicly attributed activity centers on unauthorized access to and disclosure of politically sensitive information rather than financially motivated crime or ransomware. The group’s operations, as reported, involved obtaining internal communications and documents from a high-profile Russian political target and publishing them to influence public understanding of Russian involvement in Ukraine. This indicates capabilities in initial access and exfiltration, with the operation’s impact deriving primarily from information theft and strategic disclosure. Available reporting does not provide high-confidence evidence for broader intrusion tradecraft, malware development, or destructive activity beyond the compromise and leak operation. CyberJunta has been associated with the Russia-Ukraine conflict information environment and appears aligned with Ukrainian interests. Its known targeting in the available record is political and governmental in nature, focused on Russian state-linked figures involved in Ukraine-related affairs. Little verified information is publicly available about the group’s structure, origins, or full operational history beyond the Surkov leak operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Ukrainian hacking outfit claimed responsibility for leaking a cache of emails purportedly from Vladislav Surkov’s office related to coordination with separatist entities in eastern Ukraine.
Claimed responsibility for hacking Vladislav Surkov and releasing emails and documents allegedly detailing Kremlin plans to destabilize Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.