RuskiNet is a pro-Russian hacktivist collective active in conflict-driven disruptive operations and aligned with the broader Russian hacktivist ecosystem. It has been described as operating in coordination with NoName057(16) and as part of the cyber dimension of the Russia-Iran strategic partnership that deepened after 2022. Reported functions associated with the group include distributed denial-of-service operations, support to data leak activity, provision of TOR relay infrastructure, and military intelligence exfiltration capabilities. Operationally, RuskiNet has been associated primarily with disruptive campaigns against NATO-aligned, Western-friendly, and Israeli targets. During the March 2026 regional escalation tied to Operation Epic Fury, the group was reported to have conducted daily DDoS attacks against Israeli industrial targets. Its activity fits a broader pattern of politically motivated, propaganda-amplified cyber operations in which disruptive effects and symbolic targeting are central. Known aliases include ruskinet and ruskinet_group. High-confidence reporting supports characterization of RuskiNet as a pro-Russian actor focused on disruptive and supporting cyber operations rather than a ransomware-centric criminal enterprise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian DDoS collective coordinating with NoName057(16) to target NATO-aligned and Western-friendly infrastructure.
Pro-Russian-aligned group conducting daily DDoS attacks on Israeli industrial targets during the 2026 escalation.
Low-profile actor conducting daily DDoS attacks and republishing older leaked data to maintain pressure against Israeli industrial and financial targets.
Russian-linked actor supporting the Russia-Iran cyber axis by providing TOR relay infrastructure, data leak operations, and military intelligence exfiltration capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.