Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors EvilWeb

Also known as: APT28, Cozy Bear, Pawn Storm, Sednit, STRONTIUM, Sofacy, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code, Russian Cyber Army Team, Ukraine began

Description

EvilWeb is a pro-Russian hacktivist group created in March 2024 that targets American and European entities using a hack-and-leak method alongside DDoS attacks. The group claims to have obtained data from various high-profile American organizations. EvilWeb announced its participation in the #FreeDurov operation on August 25, 2024, and began executing DDoS and hacking attacks. As of September 3, 2024, their Telegram channel has 1,146 members.

Goals & Targeting

Targeted Sectors

Defense
Media
Financial services
Government
Healthcare
Non profit
Retail
Hospitality
Energy
Information technology
Utilities
Critical infrastructure

Targeted Countries / Regions

US
FR
IL
RU
IR
SA
TR
UA
PL

AI Analysis

· 1 week ago

Executive Summary

EvilWeb is a pro-Russian hacktivist group launched in March 2024, targeting American and European entities through DDoS attacks and data breaches. The group, active since August 2024, has targeted high-profile organizations and employs a hack-and-leak strategy to disseminate sensitive information. EvilWeb's operations are likely influenced by geopolitical tensions and align with pro-Russian narratives.

Goals & Targeting

EvilWeb appears motivated by anti-American and pro-Russian sentiment, targeting entities aligned with Western interests. Their hack-and-leak campaigns aim to undermine trust in American institutions while supporting Russian-aligned narratives surrounding figures like Nikolai Durov. The group's targeting of sectors such as technology, finance, and government reflects an intention to maximize impact and attention.

Enhanced Description

EvilWeb emerged in March 2024 as a self-proclaimed pro-Russian hacktivist collective, gaining notoriety for its participation in the #FreeDurov operation in August 2024. The group's primary activities include DDoS attacks and data exfiltration from Western organizations, with claims of successful breaches of high-profile targets. EvilWeb operates openly on platforms like Telegram, where its channel has amassed over 1,000 members by early September 2024. While the group positions itself as a grassroots movement, its operational sophistication suggests possible connections to more established cyber actors or state-sponsored groups.

Key Capabilities

  • Conducting DDoS attacks using botnets
  • Performing network exploitation for data theft
  • Using hack-and-leak tactics for信息发布和舆论压力
  • Leveraging open-source intelligence (OSINT) tools
  • Coordinating via暗网 platforms like Telegram

MITRE ATT&CK Tactics

Disruption
Collection
Reconnaissance

ATT&CK Techniques

T1486.002 - Disruptive Activities: DDoS Execution Through Traffic Flooding
T1503.001 - Data Destruction
T1576.004 - Exfiltration Over Alternative Protocol
T1203.003 - Exploitation Framework Injection
T1566.001 - Phishing for Information Gathering

Software / Tooling

Qbot
Mirai botnet derivatives
Custom DDoS tools
OSINT tools like theHarvester, Maltego

Campaigns & Victims

EvilWeb's campaign patterns suggest a focus on high-profile targets to maximize media attention and political impact. Their operational timeline indicates rapid execution since their August 2024 announcement, with early September activities already showing signs of increased coordination among members. While the group is relatively new, its growth rate and membership size indicate potential for escalation in scale and complexity.

IOC Patterns

  • Sudden spikes in network traffic indicative of DDoS attacks
  • Presence of botnet command-and-control servers
  • Phishing emails targeting organizational staff
  • Data dumps on暗网 forums orpasteBIN-like sites

Recommended Actions

  • Implement DDoS protection measures and traffic monitoring
  • Conduct regular security audits to mitigate potential breach risks
  • Monitor employee communications for phishing attempts
  • Establish protocols for rapid response to data breaches
  • Educate employees about suspicious activities related to暗网

Suggested Tags

Pro-Russia
Hacktivism
DDoS
APT-like
Geopolitical Motivation

Confidence Assessment

Low confidence due to limited operational history and lack of concrete details on tools, infrastructure, or long-term goals. While EvilWeb's declared activities and Telegram activity are clear indicators of their intent, the absence of detailed attack vectors and data dumps leaves uncertainty about their capabilities and affiliations.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. blog.checkpoint.com — Cited by web research for: Russian Cyber Army Team
  3. www.recordedfuture.com — Cited by web research for: T1497
  4. attack.mitre.org — Cited by web research for: PowerShell
  5. www.proofpoint.com — Cited by web research for: STOP

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

DDoS
Hacktivism
Pro-Russia
APT-like
Geopolitical Motivation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.