CyberBerkut was a purported pro-Russian hacktivist persona active from 2014 that has been widely linked by governments and security researchers to Russian state interests, including the GRU, and in some reporting to the Sofacy/APT28 cluster. It emerged during Russia’s campaign against Ukraine and was used to provide plausible deniability for cyber and information operations aligned with Kremlin objectives. CyberBerkut is best known for operations against Ukrainian targets during and after the 2014 Crimea crisis, including attacks on Ukrainian ministries and the Central Election Commission. Reported activity against the election infrastructure included system compromise, data destruction, data leakage, distributed denial-of-service attacks, and attempted website defacement with false election results, illustrating a focus on disrupting the transmission and perception of results rather than altering ballots directly. The group also conducted website defacements and denial-of-service attacks during the broader conflict. Beyond Ukraine, CyberBerkut claimed or was associated with disruptive operations against NATO-related websites and was cited in connection with targeting of the German Bundestag, U.S. defense-related entities, and influence activity tied to broader Russian active measures. The persona was used not only for network attacks but also for hack-and-leak and propaganda operations, publishing stolen material as well as fabricated or manipulated content intended to discredit Ukraine, NATO, and Kremlin opponents. This combination of intrusion, disruption, leaking, and disinformation made CyberBerkut part of a wider Russian ecosystem of false-front or proxy personas used to obscure state responsibility while advancing espionage and influence goals. Known aliases include cyberberkut and cyber_berkut.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist-style group involved in DDoS attacks and website defacements during the Ukraine/Crimea conflict to create confusion and disruption.
Pro-Moscow hacking collective involved in cyber operations during Russia’s invasion of Ukraine, including website defacements in Ukraine.
Referenced as the actor behind operations during Ukraine's 2014 presidential election that disrupted election authorities and interfered with official election result announcements, illustrating an attack model focused on election communications and disinformation rather than altering vote totals directly.
Conducting disinformation and influence operations using fabricated videos and photos, including efforts to discredit Ukrainian authorities and a Russian opposition figure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.