Also known as: AlphaVM, AlphaV, Secret Blizzard, tracked as, the Newscaster Team, 2026, ALPHV, Google Sheets, personal photos, an
Formed in 2016, Cyber Alliance evolved into a pro‑Ukraine hacktivist umbrella that rose to prominence following the Russia‑Ukraine conflict in 2022. The group has publicly claimed responsibility for high‑profile incidents such as the sabotage of Russian internet provider Nodex and a data breach against microfinance company CarMoney, which reportedly had connections to Vladimir Putin’s ex‑wife. Cyber Alliance’s campaign catalog is marked by widespread use of destructive malware—often delivering file encryption or direct file deletion—and routine exploitation of public‑facing services. The actors frequently rely on social engineering (phishing emails with malicious attachments) and publicly post progress updates through encrypted messaging platforms, positioning themselves as a pro‑military counter‑offensive against Russian influence. Cyber Alliance leverages a mix of known offensive tools such as mshta, Cobalt Strike, and various ransomware families (e.g., Akira, BlackCat). Their toolkit also features utility scripts (defoff.bat, turnoff.bat) for system shutdown or data suppression. While the group claims ideological motivation, financial gain remains a stated primary driver; ransom demands and direct theft of funds from compromised accounts are common. The organization maintains a robust online presence that includes Telegram channels, obfuscated domains, and self‑certified web pages used to orchestrate command-and-control operations. In recent months Cyber Alliance has expanded its scope to include sectors such as telecommunications, defense, critical infrastructure, healthcare, and non‑profits across the United States, Russia, China, and several EU member states. The group’s operational tempo is variable; it can launch rapid sabotage campaigns while also conducting longer reconnaissance missions on target networks before executing destructive payloads.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Cyber Alliance is a Ukrainian hacktivist group active since 2016 that primarily targets Russian entities following Ukraine’s full‑scale invasion in 2022. Its operations combine destructive malware campaigns against critical infrastructure with social engineering tactics, aiming to disrupt enemy communications and acquire financial gains. The group publicly showcases its attacks on social media and routinely claims responsibility for sabotage incidents across a broad spectrum of sectors.
Goals & Targeting
Cyber Alliance’s strategic objectives blend ideological defiance against Russian influence with financial exploitation. By targeting critical infrastructure in telecommunications, government, defense, and energy sectors—particularly within Russia, Ukraine, and allied European states—the group seeks to cause operational disruption, damage reputations, and compel victims into ransom negotiations or asset theft. Secondary targets include microfinance firms and state‑linked enterprises, often used as high‑profile bait to amplify the impact of attacks. The typical victim is an entity with either a strategic national role or significant public visibility that can be leveraged for propaganda value.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Cyber Alliance’s campaign style can shift from one‑shot sabotage to multi‑stage operations. Early activity in 2022 was marked by rapid destructive attacks against Russian ISP infrastructure, followed by targeted phishing campaigns aimed at defense ministries and telecom firms. Recent reports suggest the group employs a dual strategy: high‑impact destructive payloads (e.g., file deletion or ransomware) combined with ongoing social engineering to infiltrate lower tiers of organizations for future lateral movement. Operational tempo has fluctuated—short bursts of activity during high‑tension periods, with quieter reconnaissance phases in between. Victim selection leans heavily toward entities that will provide high visibility and a strong political narrative when attacked. Notable past operations include the Nodex sabotage incident (reported by Ukrainian security channels), the CarMoney breach where financial data was exfiltrated and ransom demands were issued, and widespread phishing campaigns on social platforms in 2023 that compromised dozens of European government agencies’ email accounts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the reported operational details is moderate. Core claims about Cyber Alliance’s Ukrainian origin, pro‑Ukraine stance, and focus on Russian targets are supported by publicly referenced incident reports (e.g., Nodex sabotage). However, many of the technical attributes—tool usage, specific ATT&CK techniques, and broad sector coverage—come from secondary or conflated sources that include unrelated threat groups (such as Turla and SolarWinds). The list of associated tools may over‑estimate capabilities due to overlap with other actors’ toolsets. Additional intelligence is required to confirm the frequency, effectiveness, and exact deployment methods for each capability, particularly regarding ransomware operations and financial motives.
No campaigns linked yet.
No observed data linked yet.
24
Techniques
44
Tools
0
Campaigns
19
IOCs
0
Observed Data
6
Tactics