Legion Null is a hacktivist group publicly identified as active during the first half of 2026. It has been listed alongside other prominent hacktivist actors such as IT ARMY OF RUSSIA, BLAZER TEAM ATTACK, Brotherhood Capung BCI, Lystic Team #ID, and NoName057(16). Available reporting places Legion Null within the broader contemporary hacktivist ecosystem characterized by disruptive operations and increasing overlap with financially motivated cyber activity. Across that ecosystem, commonly observed behaviors include exploitation of public-facing applications, spearphishing links, use of valid accounts, deployment of web shells, exfiltration over web services, data encryption for impact, and network denial-of-service activity. High-confidence, actor-specific details on Legion Null’s origin, victimology, tooling, or operational history are currently not available from the supplied information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.