Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Inteid

Also known as: APT28, Fancy Bear, tracked as, Pawn Storm, the Infrastructure Destruction Squad, Golden Falcon Team, S4uD1Pwnz, Sector 16, Fa, APT29, a German academic institution, Sandworm, APT 44, affiliated wi, under, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, APT44, Sednit

Description

Inteid is a member of the Russian Legion alliance, a coalition that includes groups such as Cardinal and The White Pulse. The group has been linked to both DDoS activities and more sophisticated offensive actions against industrial control system environments., One notable incident involved a coordinated DDoS campaign against Denmark’s national health portal, sundhed.dk, which disrupted access for healthcare providers and patients alike. In addition, Inteid has conducted prolonged incursions into Energy & Utilities, Manufacturing, and Agriculture subsectors across the European Union, targeting operational technology networks to cause production outages or service degradation., The group demonstrates a propensity for collaboration with other hacktivist entities; its partnership with Keymous+ underlined a joint effort to support Iranian cyberwar campaigns against Israeli targets. This coordination illustrates Inteid’s geopolitical alignment and ability to operate in conjunction with state‑aligned adversaries., Inteid employs a variety of malware families, including advanced Remote Access Trojans (RATs) such as 9002 RAT, Poison Ivy, and custom backdoors delivered through phishing vectors. The actor also exploits well-known ransomware variants like BlackByte and LockBit to amplify pressure on victims or to extract additional leverage from compromised networks.

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Defense
Maritime
Financial services
Manufacturing
Transportation
Media
Energy
Healthcare
Education
Utilities
Pharmaceutical
Telecommunications
Aerospace
Nuclear
Food agriculture
Aviation
Information technology
Retail

Targeted Countries / Regions

RU
UA
US
AE
PL
RO
DE
GB
IT
ES
IR
IL
SA
SY
NL
FR
CA

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

Inteid is a Russian‑aligned hacktivist group active in large‑scale Distributed Denial of Service and industrial control system (ICS) attacks across Europe, particularly targeting Energy & Utilities, Manufacturing, and Agriculture sectors. The actor has coordinated with other groups to support Iranian cyberwar efforts and frequently targets government and critical infrastructure. Its operations aim to disrupt services rather than profit from data theft or ransom.

Goals & Targeting

Inteid’s strategic objectives revolve around political disruption rather than financial gain. By targeting sovereign governments, critical infrastructure operators, and high‑visibility public utilities in EU and NATO member states, the group seeks to undermine confidence in state‐backed services and to create pretext for broader cyber operations aligned with Russian foreign policy objectives. The inclusion of maritime, transport, and healthcare sectors further hints at a focus on multi‑sector resilience attacks designed to expose systemic vulnerabilities.

Enhanced Description

Key Capabilities

  • Launch large‑scale DDoS campaigns using botnets or custom scripts
  • Deploy spear‑phishing emails with malicious attachments or links
  • Install and maintain stealthy Remote Access Trojans (9002 RAT, Poison Ivy, GoSerpent)
  • Exploit industrial control system networks to disrupt operations
  • Use ransomware (BlackByte, LockBit) for extortion or escalation of pressure
  • Coordinate with other hacktivist groups (Keymous+, Dark Engine) for joint actions
  • Leverage social engineering and domain generation algorithms for command & control
  • Harvest credentials via Mimikatz and other credential dumping tools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1566.001 – Spearphishing Attachments
T1105 – Ingress Tool Transfer
T1059.006 – PowerShell
T1071.002 – Web Protocols (HTTP/HTTPS)
T1040 – Network Sniffing
T1083 – File and Directory Discovery
T1021.001 – Remote Services: SSH
T1021.004 – Remote Services: RDP
T1075 – Pass the Hash
T1055 – Process Injection
T1496 – Resource Hijacking (DDoS)
T1204 – User Execution

Software / Tooling

9002 RAT
Poison Ivy
GoSerpent
BlackByte Ransomware
LockBit
BlackCat (Eminence)
SUNBURST (Cobalt Strike variant)
TEARDROP
InvisiMole
Anchor
Explosive

Campaigns & Victims

Inteid operates on a rapid operational tempo, mounting repeated DDoS and OT attacks during high‑profile geopolitical events. Its campaigns typically involve coordinated phishing spear‑phish vectors, delivery of custom RATs for persistence, and subsequent exploitation of industrial protocols such as Modbus/TCP or OPC UA. Victims are primarily located in EU Member States, NATO partners, and Israel – with a notable focus on energy utilities, manufacturing plants, and agricultural facilities. Recent operations demonstrate a shift toward integrating ransomware components after initial disruption to maximize leverage.

IOC Patterns

  • Spear‑phishing emails with malicious Office document attachments or obfuscated script links
  • Command and Control over encrypted TLS/HTTPS channels
  • Domain generation algorithms yielding country code top‑level domain (ccTLD) variations for staging
  • Use of fast‑flux DNS to hide botnet command servers
  • Large‑scale DDoS traffic spikes originating from compromised IoT devices or volunteer botnets

Recommended Actions

  • Implement rigorous email filtering and sandboxing for attachments and URLs, especially those referencing foreign ccTLDs.
  • Deploy network segmentation with strict access controls between operational technology (OT) networks and enterprise IT systems.
  • Continuously monitor for abnormal traffic patterns that could indicate DDoS initiation or compromise of OT processes.
  • Apply security hardening on critical infrastructure assets: patching, disabling unused protocols, enforcing firewall rules to limit inbound/outbound connections.
  • Conduct regular red‑team exercises focusing on spear‑phishing and credential theft scenarios against engineering and IT staff.

Suggested Tags

APT
hacktivist
industrial control system (ICS) attack
energy sector
utility infrastructure
government targeting
DDoS
phishing

Confidence Assessment

The assessment is based primarily on a Kaspersky press release detailing recent InT eid campaign data and a few Malpedia entries indicating malware families used by the group. Direct evidence of the actor’s capabilities beyond these sources is limited, and some alias information appears inconsistent or speculative. Therefore confidence in specific tool associations is moderate; however, overall conclusions about TTPs (phishing, DDoS, IC attacks) have high confidence given repeated reports across independent security vendor publications.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Email Address 1 Domain 18 Filename 1

References

  1. thecyberexpress.com — Cited by web research for: the Infrastructure Destruction Squad
  2. sahasec.org — Cited by web research for: Fa
  3. www.kaspersky.com — Cited by web research for: Mirage Kitten
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.9002 — Cited by AI analysis.
  5. https://malpedia.caad.fkie.fraunhofer.de/details/win.poison_ivy — Cited by AI analysis.

Intel Summary

13

Techniques

45

Tools

0

Campaigns

24

IOCs

0

Observed Data

2

Tactics

Tags

Critical Infrastructure
DDoS
Hacktivism
APT
Cyber Espionage
Geopolitical
hacktivist
industrial control system (ICS) attack
energy sector
utility infrastructure
government targeting
phishing

Details

Type
Unknown
Primary Motivation
Disruption
Country of Origin
Russia (RU)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.