Guccifer 2.0 was an online persona used during the 2016 U.S. presidential election to claim responsibility for intrusions into Democratic Party organizations and to disseminate stolen political documents. The persona presented itself as a lone Romanian hacker, but U.S. government indictments and broad security-industry analysis have attributed the activity to Russian military intelligence officers of the GRU as part of a deception and influence operation. Guccifer 2.0 was used to obscure Russian responsibility for the compromises, promote and selectively leak stolen material, and channel data to amplifiers including WikiLeaks. The persona emerged immediately after public reporting on the Democratic National Committee compromise and claimed responsibility for hacking the DNC, later also releasing material associated with the Democratic Congressional Campaign Committee and making additional claims about other Democratic-linked targets. Multiple analyses cited strong links between the underlying intrusions and Russian state-sponsored operators commonly tracked as Fancy Bear and Cozy Bear, while Guccifer 2.0 itself functioned as a cover identity intended to undercut attribution and shape public perception. Operationally, Guccifer 2.0 is associated with theft and publication of politically sensitive documents, exposure of personal information, and direct engagement with media figures and political intermediaries. The persona publicly released stolen files, claimed to have provided email troves to WikiLeaks, and was referenced in reporting and indictments concerning Russian efforts to use online personas and third parties to spread hacked material during the election. The activity combined cyber intrusion support, information operations, deception, and exfiltration rather than ransomware or financially motivated crime. Known aliases include guccifer20 and guccifer_20. High-confidence reporting ties the persona to Russian active measures targeting U.S. political organizations, especially Democratic institutions, in support of broader election interference objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Persona associated with the theft and release of Democratic National Committee emails as part of election-related influence and disinformation activity widely believed to be tied to the Kremlin.
Discussed as a persona associated with the DNC leak; the content indicates analysis aimed at attributing this activity to Russia.
Guccifer 2.0 is described as the moniker used by suspected Russian intelligence operatives involved in disseminating hacked Democratic Party emails and communicating directly with WikiLeaks.
Persona tied in the article to the hacking and release pipeline around Democratic Party emails during the 2016 US election.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.