KillNet is a pro-Russian hacktivist threat actor active since at least 2022 and widely associated with politically motivated disruptive operations aligned with Russian interests. The group is best known for distributed denial-of-service campaigns against governments, public institutions, critical infrastructure, private companies, and media organizations in countries perceived as supporting Ukraine or opposing Russia. KillNet has repeatedly been described as part of the broader ecosystem of Russia-aligned patriotic or opportunistic actors that amplify pro-Kremlin narratives while conducting disruptive cyber activity. KillNet’s operations have primarily centered on DDoS attacks, often timed to geopolitical events and public policy decisions. Reported targeting has included government websites and public services in the United States, Romania, Latvia, Lithuania, Poland, Estonia, Czechia, the United Kingdom, Israel, and Ukraine, among others. The group has also been linked to attacks affecting the healthcare sector, including hospitals, health services, healthcare insurers, and pharmaceutical and life sciences organizations, as well as attacks against election-related state government services and airport-facing services. In addition to direct disruption, KillNet has been associated with propaganda amplification, public claims of responsibility, target-list publication, and symbolic support to other anti-Western hacktivist campaigns. Open reporting consistently characterizes DDoS as KillNet’s principal tactic. Observed and attributed activity includes multi-vector network- and application-layer flooding, including layer 3, layer 4, and layer 7 techniques, use of spoofed-source and amplification methods, and bot-based attacks intended to exhaust bandwidth, connection state, or CPU resources. Some reporting also places KillNet within hacktivist ecosystems that engage in website defacement, data leak claims, exfiltration, and information operations, though the group’s most consistently corroborated capability remains service disruption through DDoS. KillNet has been discussed alongside or in cooperation with other Russia-aligned actors and brands, including NoName057(16), XakNet, Cyber Army of Russia Reborn, Russian Legion, and MONARCH. Reporting has also noted collaboration or strong similarities with Anonymous Sudan in anti-Western disruptive campaigns. The actor’s public posture, target selection, and messaging indicate a dominant ideological and geopolitical alignment rather than conventional cybercrime motives, even where its operations overlap with broader influence or intimidation efforts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted DDoS attacks against U.S. state government websites in the run-up to the 2022 midterm elections.
An opportunistic anti-Western actor in the coalition, providing symbolic support, amplification, and target selection.
Killnet finally admits to working directly for the Kremlin
Named as part of the broader transnational hacktivist front contributing shared propaganda, repeated disruption, and leak operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.