Russian Legion is a pro-Russian hacktivist alliance that emerged publicly in January 2026 and has been assessed as likely state-aligned, though not necessarily state-funded. It has been described as an opportunistic anti-Western actor within broader pro-Russian and, at times, Russia-Iran-aligned cyber mobilization ecosystems. Known associated names and components include MONARCH as an alias, and member groups Cardinal, The White Pulse, Russian Partizan, and Inteid. The group is primarily associated with disruptive operations, political coercion, and information effects rather than advanced intrusion tradecraft. Its activity has centered on public threats, Telegram-based messaging, target amplification, and distributed denial-of-service campaigns used to pressure governments and shape public perception around geopolitical events. In early 2026 it announced OpDenmark, a campaign threatening large-scale cyberattacks against Denmark in retaliation for Danish military aid to Ukraine, with repeated references to Danish public-sector and energy-sector targets. Reporting also links Russian Legion to claimed disruptive activity against Israeli municipal authorities, political entities, telecommunications providers, and defense-related organizations during the 2026 Iran-Israel escalation, including support for Iran-aligned narratives. Russian Legion has also been characterized as part of the cyber dimension of the Russia-Iran strategic partnership, with attributed roles including support infrastructure, data leak operations, and military intelligence exfiltration capabilities. Across reporting, however, many of its public claims appear to fit the broader hacktivist pattern of exaggeration, symbolic targeting, and psychological pressure. Its observed methods and claimed behaviors include DDoS operations, exfiltration, propaganda amplification, target selection support, and politically themed intimidation campaigns. The actor’s dominant orientation is geopolitical and anti-Western, aligning its operations with Russian strategic interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An opportunistic anti-Western actor providing symbolic support, amplification, and target selection within the coalition.
Pro-Russian hacktivist group participating in the pro-Iran coalition during the conflict.
Group cited as participating in similar cyber activity during the conflict.
Pro-Russian hacktivist group claiming breaches of Israeli military networks, including the Iron Dome missile defense system.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.