NB65 is a pro-Ukraine hacktivist group active during Russia’s 2022 invasion of Ukraine. The group is known for targeting Russian organizations, initially through intrusions, data theft, and public leaking of stolen information, and later through ransomware attacks. NB65 publicly framed its operations as retaliation for Russia’s invasion of Ukraine and stated that it would confine targeting to Russian entities. NB65 is notable for building ransomware from the leaked source code of Conti and modifying the malware for victim-specific deployments. Public reporting linked the group to attacks against Russian organizations including state-affiliated and high-profile entities such as Roscosmos and the Russian state broadcaster VGTRK. The group also claimed responsibility for disruptive operations against major Russian television networks. Its operations combined hacktivist messaging with capabilities more commonly associated with criminal ransomware activity, including file encryption, ransom demands, and anti-decryption modifications intended to prevent use of existing Conti decryptors. The actor’s observed tradecraft includes initial compromise of Russian entities, theft and exfiltration of data, public leaking of stolen material, disruptive attacks, and ransomware deployment. NB65’s activity reflects a politically motivated adaptation of leaked criminal tooling for retaliatory cyber operations rather than conventional financially driven ransomware operations. The group has been associated with the broader Anonymous-aligned pro-Ukraine ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hacktivist-aligned ransomware and data theft operations targeting Russian organizations in response to Russia's invasion of Ukraine, using a modified ransomware built from leaked Conti source code.
Anonymous-affiliated group conducting breaches and disruptive operations against Russian television networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.