Also known as: APT28, Fancy Bear, tracked as, Pawn Storm, the Infrastructure Destruction Squad, Golden Falcon Team, S4uD1Pwnz, Sector 16, Fa, APT29, a German academic institution, Sandworm, APT 44, affiliated wi, under, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, APT44, Sednit
Inteid is a member of the Russian Legion alliance, a coalition that includes groups such as Cardinal and The White Pulse. The group has been linked to both DDoS activities and more sophisticated offensive actions against industrial control system environments., One notable incident involved a coordinated DDoS campaign against Denmark’s national health portal, sundhed.dk, which disrupted access for healthcare providers and patients alike. In addition, Inteid has conducted prolonged incursions into Energy & Utilities, Manufacturing, and Agriculture subsectors across the European Union, targeting operational technology networks to cause production outages or service degradation., The group demonstrates a propensity for collaboration with other hacktivist entities; its partnership with Keymous+ underlined a joint effort to support Iranian cyberwar campaigns against Israeli targets. This coordination illustrates Inteid’s geopolitical alignment and ability to operate in conjunction with state‑aligned adversaries., Inteid employs a variety of malware families, including advanced Remote Access Trojans (RATs) such as 9002 RAT, Poison Ivy, and custom backdoors delivered through phishing vectors. The actor also exploits well-known ransomware variants like BlackByte and LockBit to amplify pressure on victims or to extract additional leverage from compromised networks.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Inteid is a Russian‑aligned hacktivist group active in large‑scale Distributed Denial of Service and industrial control system (ICS) attacks across Europe, particularly targeting Energy & Utilities, Manufacturing, and Agriculture sectors. The actor has coordinated with other groups to support Iranian cyberwar efforts and frequently targets government and critical infrastructure. Its operations aim to disrupt services rather than profit from data theft or ransom.
Goals & Targeting
Inteid’s strategic objectives revolve around political disruption rather than financial gain. By targeting sovereign governments, critical infrastructure operators, and high‑visibility public utilities in EU and NATO member states, the group seeks to undermine confidence in state‐backed services and to create pretext for broader cyber operations aligned with Russian foreign policy objectives. The inclusion of maritime, transport, and healthcare sectors further hints at a focus on multi‑sector resilience attacks designed to expose systemic vulnerabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Inteid operates on a rapid operational tempo, mounting repeated DDoS and OT attacks during high‑profile geopolitical events. Its campaigns typically involve coordinated phishing spear‑phish vectors, delivery of custom RATs for persistence, and subsequent exploitation of industrial protocols such as Modbus/TCP or OPC UA. Victims are primarily located in EU Member States, NATO partners, and Israel – with a notable focus on energy utilities, manufacturing plants, and agricultural facilities. Recent operations demonstrate a shift toward integrating ransomware components after initial disruption to maximize leverage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on a Kaspersky press release detailing recent InT eid campaign data and a few Malpedia entries indicating malware families used by the group. Direct evidence of the actor’s capabilities beyond these sources is limited, and some alias information appears inconsistent or speculative. Therefore confidence in specific tool associations is moderate; however, overall conclusions about TTPs (phishing, DDoS, IC attacks) have high confidence given repeated reports across independent security vendor publications.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
45
Tools
0
Campaigns
24
IOCs
0
Observed Data
2
Tactics