Legion is a name used in at least two distinct cyber contexts, but the high-confidence threat-actor reporting here supports Legion as a pro-Russian hacktivist or criminal group associated with disruptive distributed denial-of-service activity. Norwegian authorities linked Legion to attacks that disrupted important websites and online services, placing the group within the broader ecosystem of pro-Russian actors used in coercive and influence-oriented cyber operations against countries supporting Ukraine. The group’s observed activity is consistent with disruptive operations intended to create insecurity and public pressure rather than covert espionage or financially motivated intrusion. Separately, Legion is also referenced as a cloud-focused infostealer or attack tool family related to other credential-harvesting malware such as AlienFox, GreenBot, and Predator. In that tooling context, Legion has been described as sharing functional similarities with FBot and as likely incorporating adapted code. Because the available facts do not firmly establish whether the same operator is responsible for both the pro-Russian disruptive activity and the Legion cloud-stealer tooling, these should not be conflated beyond the shared name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cloud infostealer related to FBot, sharing similar functionality for scraping URLs for PHP configuration and targeting cloud/service credentials.
Legion is a pro-Russian criminal group known for conducting DDoS attacks against important websites and online services, disrupting operations as part of broader Russian-aligned cyber activities.
Legion Hacktivist Group
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.