Belarusian Cyber Partisans is a Belarusian hacktivist group that emerged after the 2020 protests against President Alexander Lukashenko. The group is openly anti-Lukashenko, anti-Russian in the context of the war against Ukraine, and aligned with political objectives such as disrupting Belarusian support to Russian military operations. It has been publicly described as supporting Ukraine and opposing the Belarusian regime, and has claimed operations intended to hinder Russian troop movements through Belarus. The group is known for intrusions against Belarusian state institutions, government-related organizations, and transportation infrastructure, especially the Belarusian railway network. It has also been linked to operations against Russian targets, including cooperation with Silent Crow in the July 2025 Aeroflot attack, which the groups said followed a long-term penetration of the airline’s network and involved destructive impact and data theft. Belarusian Cyber Partisans has also stated that information obtained from hacked Russian entities was shared with Ukrainian intelligence services and Western organizations. Documented tradecraft attributed to the group includes exploitation of public-facing remote access services, including use of CVE-2019-0708 for initial access; credential theft with Mimikatz; reconnaissance with network-scanning tools; lateral movement via RDP; persistence through port forwarding and exposed remote access; and destructive or disruptive actions including deletion of data and ransomware-style attacks against railway information systems. Public reporting also ties the group to website defacements and broader disruptive operations against critical infrastructure and government institutions in Belarus and Russia. In at least one politically motivated railway operation, the group’s demands centered on political concessions and military withdrawal rather than financial payment. Known aliases include Belarusian Cyber-Partisans, Belarusian Cyberpartisans, and Belarusian Cyber Partisans. The group has been characterized as a hacktivist actor rather than a conventional cybercriminal enterprise, with operations focused on political disruption, anti-regime activism, and support for Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Included as contextual background on actors capable of targeting Russian infrastructure; not linked by evidence to the dairy-sector incidents in this report.
Hacktivist group that emerged after the 2020 Belarus protests and has conducted cyber operations against Belarusian state institutions, the Belarusian railway network, and Russian entities; it also claimed involvement in the 2025 Aeroflot attack and said it shared hacked information from Russian entities with Ukrainian intelligence services and Western organizations.
Referenced as an example hacktivist group in a framework discussing the hacktivism ecosystem and how such activity can be used to obscure intent and shape narratives.
Hacktivist group cited as co-responsible for the Aeroflot attack that caused major flight disruptions and allegedly involved data theft and server wiping.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.