Wagner Group is a Russia-linked private military and mercenary organization closely associated with Yevgeny Prigozhin and used for deniable military, security, and influence operations in support of Russian state interests. Despite formal legal ambiguity around mercenary activity in Russia, Wagner has long operated as a proxy force aligned with Kremlin objectives and has been described as a predecessor to the Russian Ministry of Defense-controlled Africa Corps in parts of Africa. Wagner has been active in Ukraine, Syria, Libya, Mali, and other theaters, where it has supported combat operations, regime protection, counterinsurgency, and Russian geopolitical influence. In Ukraine, Wagner fighters operated alongside Russian and separatist forces, were reportedly involved in attempts to target senior Ukrainian leadership during the opening phase of the 2022 full-scale invasion, and became associated with highly attritional infantry tactics later adopted more broadly by Russian forces. In Africa, especially Mali, Wagner and later Africa Corps supported Malian armed forces against Tuareg rebel groups and jihadist organizations while also advancing Russian influence and resources-for-security arrangements. The group is widely associated with serious abuses against civilians and prisoners, including torture, extrajudicial killings, mutilation, and other conduct that has been characterized as potential war crimes and crimes against humanity in multiple theaters. Wagner has also been linked to public dissemination of graphic violence through affiliated Telegram channels as part of intimidation and psychological operations. In April 2023, Prigozhin publicly ordered Wagner fighters to kill everyone on the battlefield and take no prisoners, conduct widely regarded as violating the prohibition on declaring no quarter. Beyond kinetic operations, Wagner has been tied to broader Russian influence and covert activity. Prigozhin was linked not only to Wagner but also to Russian information operations infrastructure, and Wagner has been referenced in connection with sabotage, proxy violence, and deniable foreign operations in Europe and Africa. The organization has relied on plausible deniability, shell structures, close ties to Russian security elements, and coordination with state objectives to blur the line between private force and state instrument. Known aliases include Wagner and Wagner Group. Its successor structure in parts of Africa is Africa Corps.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in unrelated post navigation / related content, not part of the article's core subject.
Mentioned as the group led by Yevgeny Prigozhin, who created the Foundation to Battle Injustice operation discussed in the report.
Predecessor Russian force to Africa Corps in Mali; mentioned as historical context and through affiliated social media channels/accounts tied to reporting around the strikes.
Mentioned as an example of openly state-linked activity excluded from the report’s gray-zone scope because deniability is absent.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.