Russian Cyber Army is a pro-Russia hacktivist group active in campaigns aligned with Russian geopolitical interests, particularly the war against Ukraine. It has been observed operating in parallel with NoName057(16) since at least late 2022 and is commonly associated with disruptive denial-of-service activity against government and critical-sector targets. Reporting has linked the group to attacks on Ukrainian organizations and to retaliatory operations against foreign states perceived as supporting Ukraine, including attacks on Japanese government websites after Tokyo announced support for Kyiv. The group has also been identified as one of the more active Russian-affiliated entities targeting Ukraine. Its operations are characterized primarily by distributed denial-of-service attacks intended to cause temporary outages and public disruption rather than covert long-term intrusion. Targeting has included government entities, and broader reporting on attacks against Ukraine places activity in critical infrastructure, technology, transportation, energy, media, and education among the affected sectors. Russian Cyber Army is frequently discussed alongside NoName057(16), another pro-Russia hacktivist collective known for DDoS-focused operations, though the two are treated as distinct groups. Available information supports classifying Russian Cyber Army as a politically aligned disruptive actor with hacktivist characteristics rather than a conventional espionage or financially motivated intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russia hacktivist-aligned group operating since late 2022 in parallel with Noname057(16); associated with DDoS-style activity and alleged state-structure links/funding.
Pro-Russia hacktivist group conducting DDoS attacks against foreign government websites aligned against Russian interests.
Russian Cyber Army is a Russian-affiliated group conducting cyberattacks against Ukraine, focusing on government and critical infrastructure targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.