Also known as: TA471, SaintBear, Lorec53, Dukes, Cozy Bear, Fancy Bear, tracked as, Black Energy, BlackEnergy, ELECTRUM, Iron Viking, Quedagh, targeting the Ukrainian government, military, law enforcement officials, Group 74, Pawn Storm, SNAKEMACKEREL, STRONTIUM, Sednit, Sofacy, Swallowtail, TG-4127, Threat Group-4127, Tsar Team, UNC2589, UAC-0056, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa
RuskiNet emerged in early 2025 as a cyber‑terrorism actor focused on disruption of political and infrastructural targets across Europe, the United States, the Middle East and beyond. The collective is linked to a broad set of TTPs ranging from spear‑phishing via macro‑enabled Office documents and PDF links, to weaponized firmware updates that infect network devices at the lowest level. Within this framework, RuskiNet operates a sophisticated botnet engine known as Cyclops Blink to amplify DDoS attacks, which have targeted Ukrainian government sites, major corporations and even global media outlets. Their malware arsenal includes Linux kernel‑module rootkits such as Drovorub, which provide stealthy persistence and command‑and‑control capabilities, as well as the Zebrocy credential‑stealing trojan that surfaces through malicious documents uploaded to public repositories. RuskiNet also leverages remote access tools like UltraVNC via weaponized Word files, enabling prolonged control over compromised systems. Operationally, the group relies on a vast distribution network of more than 700 rotating domains and 215 IP addresses with high-speed rotation, making defensive attribution and mitigation challenging. The actor has a clear pattern of launching large‑scale DoS assaults followed by targeted defacements or data exfiltration to further its disruption agenda.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
RuskiNet is a pro‑Russian hacktivist collective conducting disruptive operations against government, critical infrastructure and commercial targets worldwide. The group uses spear‑phishing, malicious macro documents and botnets to achieve initial access, persistent remote control and large‑scale denial‑of‑service attacks. Their campaigns demonstrate both high impact disruption tactics and sophisticated malware delivery techniques.
Goals & Targeting
RuskiNet’s strategic objectives revolve around political disruption and reputational damage rather than direct intelligence gathering. By exploiting spear‑phishing vectors against a wide spectrum of entities—including government ministries, energy utilities, defense contractors, finance firms, media houses, universities, NGOs, and transportation operators—the actor seeks to undermine confidence in public institutions and sow chaos across international borders. Target selection appears opportunistic, driven by the perceived symbolic value of the victim rather than a narrow mission set, thereby reflecting its hacktivist orientation rather than state‑directed espionage goals.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RuskiNet tends to execute campaigns in rapid bursts, combining distributed denial‑of‑service waves with targeted defacement or data theft. The actor has repeatedly attacked Ukrainian government networks as a focal point while also extending attacks to NATO member states and high‑profile Western corporations. Its use of botnet activity against WatchGuard devices demonstrates an ability to exploit specific vendor weaknesses, whereas the employment of Drovorub and Zebrocy shows a readiness to pivot to Linux platforms and credential theft when opportunities arise. The group’s operational tempo is high‑frequency: new malicious domains surface almost daily, reflecting automated domain generation algorithms designed to outpace defensive blocking. Victim profiles are broad, encompassing government entities (ministry, defense, telecom), critical infrastructure (energy, transportation, maritime), finance and education sectors—any target that offers political or social leverage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in RuskiNet’s attribution and activity profile is moderate to high, supported by multiple independent threat intelligence reports noting overlapping tactics, techniques, and observed IOCs. However, confusion between naming aliases (e.g., APT28 elements appear in some sources) weakens certainty regarding the full malware palette used. Critical knowledge gaps remain concerning the actor’s exact command‑and‑control architecture, precise motivation hierarchy, and long‑term strategic objectives beyond disruption.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
49
Tools
0
Campaigns
7
IOCs
0
Observed Data
11
Tactics