Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RaHDit

Also known as: Russian Angry Hackers Did It, influence abroad

Description

RaHDit operates as a pro-Kremlin hacktivist group, primarily known for their involvement in hack-and-leak operations. They have been associated with the publication of sensitive information regarding Ukrainian military personnel and their associates, which has likely aimed to undermine Ukraine's defense efforts and support Russian narratives. The group maintains a website called NemeZida, where they disclose stolen data and coordinate attacks. RaHDit has also collaborated with other hacktivist groups, amplifying their impact on targeted sectors such as energy, government, and cyberdefense in Ukraine. Their activities include disinformation campaigns designed to manipulate public perception and support Russian military operations. Despite their claimed independent stance, there is strong evidence linking RaHDit to Russian intelligence services, making them a significant threat to Ukrainian sovereignty and NATO interests.

Goals & Targeting

Targeted Sectors

Government
Defense
Media
Hospitality

Targeted Countries / Regions

US
RU
UA
IR

AI Analysis

· 1 week ago

Executive Summary

RaHDit is a pro-Kremlin hacktivist group known for hack-and-leak operations targeting Ukraine. They have been linked to Russian intelligence, orchestrating disinformation campaigns and providing sensitive data to support Russian military narratives. Their activities pose significant risks to Ukrainian cyberdefense efforts, with potential spill-over effects on NATO-aligned targets.

Goals & Targeting

RaHDit's primary goal appears to be the destabilization of Ukraine and the promotion of pro-Russian narratives through cyberattacks and information warfare. They target sectors such as defense, energy, and cyberinfrastructure in Ukraine, as well as NATO-aligned countries opposing俄罗斯的军事行动. Their targeting strategy aligns closely with Russian geopolitical interests, aiming to weaken Ukrainian抵抗力 and influence international perceptions.

Enhanced Description

Key Capabilities

  • Hack-and-leak operations
  • Disinformation campaigns
  • Collaboration with other hacktivist groups
  • Spear-phishing
  • Data dumping on public websites
  • Cyberattacks against critical infrastructure

MITRE ATT&CK Tactics

Influence Operations
Data Exfiltration
Credential Access

ATT&CK Techniques

T1078.001 - Collection Activities via Hacked Account
T1566 - spear-phishing attachment
T1491 - DDoS

Software / Tooling

Cobalt Strike (for campaign coordination)
Mimikatz (credential dumping tool)
Custom malware frameworks (speculative)

Campaigns & Victims

RaHDit is known to conduct prolonged campaigns targeting Ukrainian military and defense sectors. Their operations often involve initial breaches followed by data exfiltration and public disclosure on platforms like NemeZida. Notable past activities include the compromise of Ukrainian military personnel's personal information, which was likely used to support Russian military operations in Eastern Europe. RaHDit’s modus operandi suggests a willingness to escalate attacks against high-value targets, potentiallyindicatingstate-levelsponsorship.

IOC Patterns

  • Spear-phishing emails targeting military and government employees
  • Data dumps on websites like NemeZida
  • DDoS activity targeting Ukrainian defense infrastructure

Recommended Actions

  • Monitor for DDoS activity against critical systems
  • Enhance phishing detection training for military personnel
  • Secure APIs and data Exfiltration points
  • Implement network segmentation to limit breach impact
  • Maintain threat intelligence feeds focused on pro-Russia hacktivist groups

Suggested Tags

Pro-Russia
Hacktivism
Information Warfare
Political Motivation
Eastern Europe

Confidence Assessment

Medium confidence in RaHDit's linkages to Russian state interests and their operational capabilities. Data gaps include specific campaign details, exact tools used, and long-term strategic goals beyond immediate military support.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.malwarebytes.com — Cited by web research for: Malwarebytes
  2. attack.mitre.org — Cited by web research for: Interception
  3. www.microsoft.com — Cited by web research for: Microsoft Teams
  4. www.microsoft.com — Cited by web research for: aea57ab930c721d271e39d2bc2c1d3a5

Intel Summary

0

Techniques

40

Tools

0

Campaigns

13

IOCs

0

Observed Data

0

Tactics

Tags

Data Exfiltration
Government Targeting
Hacktivism
Pro-Russia
Information Warfare
Political Motivation
Eastern Europe

Details

Type
Unknown
Primary Motivation
Ideology
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.