Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cyber Alliance

Also known as: AlphaVM, AlphaV, Secret Blizzard, tracked as, the Newscaster Team, 2026, ALPHV, Google Sheets, personal photos, an

Description

Formed in 2016, Cyber Alliance evolved into a pro‑Ukraine hacktivist umbrella that rose to prominence following the Russia‑Ukraine conflict in 2022. The group has publicly claimed responsibility for high‑profile incidents such as the sabotage of Russian internet provider Nodex and a data breach against microfinance company CarMoney, which reportedly had connections to Vladimir Putin’s ex‑wife. Cyber Alliance’s campaign catalog is marked by widespread use of destructive malware—often delivering file encryption or direct file deletion—and routine exploitation of public‑facing services. The actors frequently rely on social engineering (phishing emails with malicious attachments) and publicly post progress updates through encrypted messaging platforms, positioning themselves as a pro‑military counter‑offensive against Russian influence. Cyber Alliance leverages a mix of known offensive tools such as mshta, Cobalt Strike, and various ransomware families (e.g., Akira, BlackCat). Their toolkit also features utility scripts (defoff.bat, turnoff.bat) for system shutdown or data suppression. While the group claims ideological motivation, financial gain remains a stated primary driver; ransom demands and direct theft of funds from compromised accounts are common. The organization maintains a robust online presence that includes Telegram channels, obfuscated domains, and self‑certified web pages used to orchestrate command-and-control operations. In recent months Cyber Alliance has expanded its scope to include sectors such as telecommunications, defense, critical infrastructure, healthcare, and non‑profits across the United States, Russia, China, and several EU member states. The group’s operational tempo is variable; it can launch rapid sabotage campaigns while also conducting longer reconnaissance missions on target networks before executing destructive payloads.

Goals & Targeting

Targeted Sectors

Telecommunications
Government
Financial services
Energy
Defense
Critical infrastructure
Information technology
Manufacturing
Healthcare
Education
Non profit
Retail
Transportation

Targeted Countries / Regions

US
RU
RO
CN
BR
DE
GB
UA
IR
NL
FR
KP
CA
TR
ES
IT
JP

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Cyber Alliance is a Ukrainian hacktivist group active since 2016 that primarily targets Russian entities following Ukraine’s full‑scale invasion in 2022. Its operations combine destructive malware campaigns against critical infrastructure with social engineering tactics, aiming to disrupt enemy communications and acquire financial gains. The group publicly showcases its attacks on social media and routinely claims responsibility for sabotage incidents across a broad spectrum of sectors.

Goals & Targeting

Cyber Alliance’s strategic objectives blend ideological defiance against Russian influence with financial exploitation. By targeting critical infrastructure in telecommunications, government, defense, and energy sectors—particularly within Russia, Ukraine, and allied European states—the group seeks to cause operational disruption, damage reputations, and compel victims into ransom negotiations or asset theft. Secondary targets include microfinance firms and state‑linked enterprises, often used as high‑profile bait to amplify the impact of attacks. The typical victim is an entity with either a strategic national role or significant public visibility that can be leveraged for propaganda value.

Enhanced Description

Key Capabilities

  • Destructive malware delivery (data encryption and data destruction)
  • "Time-based checks" to evade static analysis
  • Use of mshta, Cobalt Strike, and remote administration utilities for persistence and lateral movement
  • Exploitation of public‑facing applications via T1190 techniques
  • Network share enumeration and exploitation in multi‑drive environments
  • Sophisticated social engineering campaigns including phishing emails with obfuscated attachments
  • System shutdown or reboot capability to cause outages
  • Defense evasion through registry Run Keys/Startup folder insertion and resource spoofing

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Command and Control
Exfiltration
Impact

ATT&CK Techniques

T1059.001: Command‑line Interface
T1033: System Owner/User Discovery
T1083: File and Directory Discovery
T1135: Network Share Discovery
T1140: Deobfuscate/Decode Files or Information
T1190: Exploit Public-Facing Application
T1497.003: Time Based Checks
T1218.005: Mshta
T1547.001: Registry Run Keys / Startup Folder
T1486: Data Encrypted for Impact
T1485: Data Destruction
T1529: System Shutdown/Reboot

Software / Tooling

Cobalt Strike
Mimikatz
mshta
Akira ransomware
BlackCat
AppleSeed
WannaCry
Sunburst
Puppet scripts (defoff.bat)
Trigon ransomware

Campaigns & Victims

Cyber Alliance’s campaign style can shift from one‑shot sabotage to multi‑stage operations. Early activity in 2022 was marked by rapid destructive attacks against Russian ISP infrastructure, followed by targeted phishing campaigns aimed at defense ministries and telecom firms. Recent reports suggest the group employs a dual strategy: high‑impact destructive payloads (e.g., file deletion or ransomware) combined with ongoing social engineering to infiltrate lower tiers of organizations for future lateral movement. Operational tempo has fluctuated—short bursts of activity during high‑tension periods, with quieter reconnaissance phases in between. Victim selection leans heavily toward entities that will provide high visibility and a strong political narrative when attacked. Notable past operations include the Nodex sabotage incident (reported by Ukrainian security channels), the CarMoney breach where financial data was exfiltrated and ransom demands were issued, and widespread phishing campaigns on social platforms in 2023 that compromised dozens of European government agencies’ email accounts.

IOC Patterns

  • Spear‑phishing emails with encrypted attachments or embedded mshta scripts
  • Domain generation algorithms producing short, random domains for command & control (e.g., demo-cloud.space)
  • Execution via custom batch files such as defoff.bat and turnoff.bat that trigger shutdown or data destruction
  • File-based indicators including mshta.exe replacements, TMBMSRV.exe, and ransomware binaries (Akira, BlackCat)
  • Use of Telegram and other encrypted messaging services for coordination
  • Deployment of remote admin tools such as AnyDesk, TeamViewer, and ScreenConnect

Recommended Actions

  • Implement whitelisting for mshta.exe and monitor its execution in real‑time.
  • Block traffic to known malicious domains (e.g., demo-cloud.space, Cyver.io) and monitor DNS queries for short, random-looking domain names.
  • Apply network segmentation and restrict access to shared drives; monitor for T1135 patterns such as NetShareEnum enumerations.
  • Enforce strict patch management to close public‑facing vulnerabilities that can be exploited via T1190.
  • Deploy host‐based intrusion detection systems to flag abnormal file deletion or system shutdown commands.
  • Conduct phishing awareness training and enable attachment sandboxing for enterprise email gateways.

Suggested Tags

APT
hacktivist
espionage
sabotage
financial-gain
ransomware
cyber‑defense
Ukranian
Russia-targeting
critical-infrastructure

Confidence Assessment

The confidence in the reported operational details is moderate. Core claims about Cyber Alliance’s Ukrainian origin, pro‑Ukraine stance, and focus on Russian targets are supported by publicly referenced incident reports (e.g., Nodex sabotage). However, many of the technical attributes—tool usage, specific ATT&CK techniques, and broad sector coverage—come from secondary or conflated sources that include unrelated threat groups (such as Turla and SolarWinds). The list of associated tools may over‑estimate capabilities due to overlap with other actors’ toolsets. Additional intelligence is required to confirm the frequency, effectiveness, and exact deployment methods for each capability, particularly regarding ransomware operations and financial motives.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.trendmicro.com — Cited by web research for: ALPHV
  2. cert.europa.eu — Cited by web research for: Google Sheets
  3. ctid.mitre.org — Cited by web research for: GitHub
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.sunburst — Cited by AI analysis.
  5. https://www.microsoft.com/security/blog/2023/07/31/russia-linked-threat-actor-turla-targets-moscow-diplomats/ — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de — Cited by AI analysis.

Intel Summary

24

Techniques

44

Tools

0

Campaigns

19

IOCs

0

Observed Data

6

Tactics

Tags

Critical Infrastructure
Government Targeting
Hacktivism
Wiper / Destructive
Geopolitical
Criminal
Disruption
APT
hacktivist
espionage
sabotage
financial-gain
ransomware
cyber‑defense
Ukranian
Russia-targeting
critical-infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
U
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.