Lystic Team #ID is a hacktivist collective identified as active in 2026. It has been listed among active hacktivist groups alongside IT ARMY OF RUSSIA, BLAZER TEAM ATTACK, Brotherhood Capung BCI, Legion Null, and NoName057(16). Available reporting places the group within broader hacktivist activity characterized by disruptive operations and overlap with criminal ecosystems, including data-sale and DDoS-for-hire dynamics. Common techniques observed across this hacktivist environment include exploitation of public-facing applications, spearphishing links, use of valid accounts, deployment of web shells, exfiltration over web services, data encryption for impact, and network denial-of-service activity. High-confidence public details on Lystic Team #ID’s specific victims, country of origin, sector focus, sub-groups, or distinctive tooling are currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of several notable North American hacktivist collectives.
Active hacktivist group highlighted in the report’s hacktivism section.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.