Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RuskiNet

Also known as: TA471, SaintBear, Lorec53, Dukes, Cozy Bear, Fancy Bear, tracked as, Black Energy, BlackEnergy, ELECTRUM, Iron Viking, Quedagh, targeting the Ukrainian government, military, law enforcement officials, Group 74, Pawn Storm, SNAKEMACKEREL, STRONTIUM, Sednit, Sofacy, Swallowtail, TG-4127, Threat Group-4127, Tsar Team, UNC2589, UAC-0056, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa

Description

RuskiNet emerged in early 2025 as a cyber‑terrorism actor focused on disruption of political and infrastructural targets across Europe, the United States, the Middle East and beyond. The collective is linked to a broad set of TTPs ranging from spear‑phishing via macro‑enabled Office documents and PDF links, to weaponized firmware updates that infect network devices at the lowest level. Within this framework, RuskiNet operates a sophisticated botnet engine known as Cyclops Blink to amplify DDoS attacks, which have targeted Ukrainian government sites, major corporations and even global media outlets. Their malware arsenal includes Linux kernel‑module rootkits such as Drovorub, which provide stealthy persistence and command‑and‑control capabilities, as well as the Zebrocy credential‑stealing trojan that surfaces through malicious documents uploaded to public repositories. RuskiNet also leverages remote access tools like UltraVNC via weaponized Word files, enabling prolonged control over compromised systems. Operationally, the group relies on a vast distribution network of more than 700 rotating domains and 215 IP addresses with high-speed rotation, making defensive attribution and mitigation challenging. The actor has a clear pattern of launching large‑scale DoS assaults followed by targeted defacements or data exfiltration to further its disruption agenda.

Goals & Targeting

Targeted Sectors

Government
Defense
Energy
Financial services
Education
Media
Critical infrastructure
Telecommunications
Think tank
Non profit
Manufacturing
Transportation
Maritime
Aviation
Healthcare

Targeted Countries / Regions

RU
IL
US
UA
IR
GB
IN
DE
EG
TR
NG
PL
CA
KP

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

RuskiNet is a pro‑Russian hacktivist collective conducting disruptive operations against government, critical infrastructure and commercial targets worldwide. The group uses spear‑phishing, malicious macro documents and botnets to achieve initial access, persistent remote control and large‑scale denial‑of‑service attacks. Their campaigns demonstrate both high impact disruption tactics and sophisticated malware delivery techniques.

Goals & Targeting

RuskiNet’s strategic objectives revolve around political disruption and reputational damage rather than direct intelligence gathering. By exploiting spear‑phishing vectors against a wide spectrum of entities—including government ministries, energy utilities, defense contractors, finance firms, media houses, universities, NGOs, and transportation operators—the actor seeks to undermine confidence in public institutions and sow chaos across international borders. Target selection appears opportunistic, driven by the perceived symbolic value of the victim rather than a narrow mission set, thereby reflecting its hacktivist orientation rather than state‑directed espionage goals.

Enhanced Description

Key Capabilities

  • Distributed denial‑of‑service (DDoS) campaigns
  • Cyclops Blink botnet operations
  • Spearfishing with macro‑enabled Office documents or PDFs
  • Malicious macros, JavaScript and LNK files in ZIP archives for delivery
  • Use of legitimate firmware update channels to inject malware into network devices
  • Phishing via a Ukrainian job‑search platform masquerading as a resume downloader
  • Weaponized Word documents deploying UltraVNC remote‑access tool
  • Domain and IP rotation across >700 domains and 215 IPs
  • Deployment of Drovorub kernel module rootkit on Linux systems
  • Distribution of Zebrocy malware through malicious documents
  • Loaders such as OutSteel and SaintBot

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Privilege Escalation
Discovery
Impact

ATT&CK Techniques

T1105
T1204
T1498.001
T1566.001
T1014
T1021.004
T1041
T1587
T1590
T1592
T1136

Software / Tooling

OutSteel
SaintBot
Cyclops Blink
Pteranodon
UltraVNC
Remote Manipulator System (RMS)
Drovorub
Zebrocy

Campaigns & Victims

RuskiNet tends to execute campaigns in rapid bursts, combining distributed denial‑of‑service waves with targeted defacement or data theft. The actor has repeatedly attacked Ukrainian government networks as a focal point while also extending attacks to NATO member states and high‑profile Western corporations. Its use of botnet activity against WatchGuard devices demonstrates an ability to exploit specific vendor weaknesses, whereas the employment of Drovorub and Zebrocy shows a readiness to pivot to Linux platforms and credential theft when opportunities arise. The group’s operational tempo is high‑frequency: new malicious domains surface almost daily, reflecting automated domain generation algorithms designed to outpace defensive blocking. Victim profiles are broad, encompassing government entities (ministry, defense, telecom), critical infrastructure (energy, transportation, maritime), finance and education sectors—any target that offers political or social leverage.

IOC Patterns

  • Spearfishing emails with macro‑enabled Office documents or PDFs
  • Links or attachments to ZIP archives containing LNK executables
  • Modified firmware images delivered via legitimate update channels
  • Rotating malicious domains and associated IP addresses

Recommended Actions

  • Implement advanced email filtering to block macro enabled attachments and phishing messages
  • Deploy sandboxing solutions for suspicious Office documents before execution
  • Patch all known vulnerabilities, including legacy CVEs
  • Secure firmware update processes by validating authenticity and integrity of images
  • Deploy or scale DDoS mitigation services and monitor traffic for volumetric attacks
  • Harden remote management protocols (RDP, SSH) and restrict unnecessary services

Suggested Tags

hacktivist
DDoS
botnet
phishing
Russia-based
Ukraine-targeting
critical infrastructure
malicious macros
Linux malware
rootkit
remote access tool
credential theft

Confidence Assessment

The confidence in RuskiNet’s attribution and activity profile is moderate to high, supported by multiple independent threat intelligence reports noting overlapping tactics, techniques, and observed IOCs. However, confusion between naming aliases (e.g., APT28 elements appear in some sources) weakens certainty regarding the full malware palette used. Critical knowledge gaps remain concerning the actor’s exact command‑and‑control architecture, precise motivation hierarchy, and long‑term strategic objectives beyond disruption.

ATT&CK Techniques

Command & Control
1 technique
Execution
1 technique
Exfiltration
1 technique
Initial Access
1 technique
Lateral Movement
1 technique
Persistence
1 technique
Stealth
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.rapid7.com — Cited by web research for: TA471
  2. learn.microsoft.com — Cited by web research for: Tsunami
  3. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl
  4. www.group-ib.com — Cited by web research for: Explosive

Intel Summary

13

Techniques

49

Tools

0

Campaigns

7

IOCs

0

Observed Data

11

Tactics

Tags

Phishing
DDoS
Government Targeting
Hacktivism
hacktivism
pro-Russian
hacktivist
botnet
phishing
Russia-based
Ukraine-targeting
critical infrastructure
malicious macros
Linux malware
rootkit
remote access tool
credential theft

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.