4BID is a pro-Ukrainian hacktivist group whose activity has primarily targeted Russian and Belarusian organizations and has expanded to Kazakhstan, the United Arab Emirates, Egypt, and Syria. It has targeted government, healthcare, and aviation entities. 4BID has been linked to a broader cluster of operationally overlapping hacktivist activity involving Hakerskii Kit, Cyber Anarchy Squad (C.A.S.), and Goffee. The group has used exploitation of Microsoft Exchange ProxyShell vulnerabilities for initial access, followed by web-shell deployment, PowerShell and command-shell execution, host and network reconnaissance, and deployment of dual-use remote-management utilities and post-exploitation frameworks. Observed tooling associated with the activity includes BlackReaperRAT, Sliver, Havoc, Mythic Apollo, AdaptixC2, BlackSalt, ClearWater ransomware, and an updated Blackout Locker variant. The operators have established persistence using local accounts, remote-access configuration, services, scheduled tasks, and startup mechanisms. They have also used defense-evasion measures including security-tool termination through bring-your-own-vulnerable-driver techniques, log cleanup, and concealment of remote-management tooling. 4BID used an updated Blackout Locker in attacks against Russian organizations in January 2026; the malware encrypts files and adds a persistent screen-locking component. The group’s campaigns combine ideologically framed pro-Ukrainian hacktivism with ransomware-enabled operations and appear to be expanding beyond their original regional focus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
111 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously associated with a closely similar malicious network-provider infection chain that was later observed, in modified form, in a Hacking Cat-linked destructive incident.
Hacktivist group whose campaigns were the primary focus of the investigation; assessed as shifting from mainly ideologically motivated attacks against Russian organizations toward financially motivated intrusions in multiple countries.
Проукраинская хактивистская группа, связанная с кампаниями против российских, белорусских, а также казахстанских, эмиратских, сирийских и египетских организаций. В исследовании ей приписываются BlackReaperRAT и использование обновленного Blackout Locker; активность указывает на расширение географии атак и возможный сдвиг от идеологической мотивации к финансовой.
Hacktivist group linked to BlackReaperRAT and updated Blackout Locker, involved in multi-country intrusions using ProxyShell exploitation, web shells, RMM tools, post-exploitation frameworks, and ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.