Also known as: APT28, Cozy Bear, Pawn Storm, Sednit, STRONTIUM, Sofacy, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, Russian Cyber Army Team, Ukraine began
EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method alongside DDoS attacks. The group claims to have obtained data from various high-profile American organizations. EvilWeb announced its participation in the #FreeDurov operation on August 25, 2024, and began executing DDoS and hacking attacks. As of September 3, 2024, their Telegram channel has 1,146 members.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
EvilWeb is a pro-Russian hacktivist group launched in March 2024, targeting American and European entities through DDoS attacks and data breaches. The group, active since August 2024, has targeted high-profile organizations and employs a hack-and-leak strategy to disseminate sensitive information. EvilWeb's operations are likely influenced by geopolitical tensions and align with pro-Russian narratives.
Goals & Targeting
EvilWeb appears motivated by anti-American and pro-Russian sentiment, targeting entities aligned with Western interests. Their hack-and-leak campaigns aim to undermine trust in American institutions while supporting Russian-aligned narratives surrounding figures like Nikolai Durov. The group's targeting of sectors such as technology, finance, and government reflects an intention to maximize impact and attention.
Enhanced Description
EvilWeb emerged in March 2024 as a self-proclaimed pro-Russian hacktivist collective, gaining notoriety for its participation in the #FreeDurov operation in August 2024. The group's primary activities include DDoS attacks and data exfiltration from Western organizations, with claims of successful breaches of high-profile targets. EvilWeb operates openly on platforms like Telegram, where its channel has amassed over 1,000 members by early September 2024. While the group positions itself as a grassroots movement, its operational sophistication suggests possible connections to more established cyber actors or state-sponsored groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
EvilWeb's campaign patterns suggest a focus on high-profile targets to maximize media attention and political impact. Their operational timeline indicates rapid execution since their August 2024 announcement, with early September activities already showing signs of increased coordination among members. While the group is relatively new, its growth rate and membership size indicate potential for escalation in scale and complexity.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited operational history and lack of concrete details on tools, infrastructure, or long-term goals. While EvilWeb's declared activities and Telegram activity are clear indicators of their intent, the absence of detailed attack vectors and data dumps leaves uncertainty about their capabilities and affiliations.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics