AzzaSec is an Italian-based hacktivist group that emerged in February 2024 with pro-Russia, anti-Israel, and anti-Ukraine positions. Its targeting includes Israel and Ukraine. Initially conducting distributed denial-of-service attacks and website defacements, the group expanded into extortion and ransomware and operated a ransomware-as-a-service model. In June 2024, AzzaSec announced a Windows ransomware builder and subsequently joined forces with Noname057(16). Its ransomware source code leaked that month and was adopted and adapted by other groups; CyberVolk and Invisible, also known as Doubleface, ransomware derive from the AzzaSec codebase. AzzaSec announced its disbandment in August 2024. Its alignment with Russian interests does not establish Russian state sponsorship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russia hacktivist group that evolved from DDoS and defacement into extortion and ransomware operations, operating a RaaS model before disbanding and seeding code reused by aligned groups.
An Italy-based, Russian-aligned hacktivist group that announced a Windows ransomware builder and subsequently joined forces with Noname057(16).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.