PalachPro is a Russian hacktivist group associated with disruptive cyber operations aligned with pro-Russian interests. It has been identified among hacktivist collectives active in periods of heightened geopolitical tension involving Ukraine and the Middle East. Public reporting links the group to claimed intrusions against Ukrainian government services, including a claim of hacking DIIA, Ukraine’s government administrative platform, although proof for that specific claim was not established in the available reporting. PalachPro has been listed alongside other disruptive hacktivist actors engaged in operations characterized primarily by service disruption and politically motivated cyber activity. Based on the available high-confidence information, PalachPro is best characterized as a pro-Russian hacktivist actor involved in disruptive operations rather than a financially motivated intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist group named as participating in disruptive operations related to the conflict.
Claimed (unverified, per the source) compromise of Ukraine’s DIIA e-government platform; reported via Telegram with limited evidence (screenshots only).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.