Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Network Battalion 65

Description

Network Battalion 65 is an hactivist group with ties to Anonymous, known for attacking Russian companies and performing hack-and-leak operations.

AI Analysis

· 1 week ago

Executive Summary

NB65, an Anonymous-affiliated hacktivist group, targets Russian companies with DDoS and hack-and-leak attacks, aiming to disrupt operations and leak sensitive data.

Goals & Targeting

NB65 appears to target sectors in Russia that are critical to national stability, such as energy, finance, and technology. The group's motivations likely stem from a dissatisfaction with Russian policies or political actions, particularly those with international repercussions. Their attacks are concentrated on Russian entities, suggesting a focus on impacting the country's economic and operational landscape through cybermeans.

Enhanced Description

NB65 is a cyber-protest collective linked to the broader Anonymous movement. They primarily conduct distributed denial-of-service (DDoS) attacks and phishing campaigns targeting Russian businesses, critical infrastructure, and government entities. The group's activities often align with hack-and-leak operations, where they seek to compromise systems to extract and publish sensitive information. Their modus operandi includes disrupting operations through DDoS, gaining unauthorized access via phishing, and leveraging stolen data for extortion or public exposure.

Key Capabilities

  • Conducting DDoS attacks
  • Launching phishing campaigns
  • Performing hack-and-leak operations
  • Using leaked data for extortion or disruption

MITRE ATT&CK Tactics

Initial Access
Impact

ATT&CK Techniques

T1076.001
T1485
T1210
T1003

Software / Tooling

Generic DDoS tools
Phishing kits
Custom-built hacking tools for specific campaigns

Campaigns & Victims

NB65 has been observed targeting energy companies, financial institutions, and government agencies in Russia. Their campaign patterns suggest a focus on high-profile victims to maximize the impact of their attacks. Campaign activity often spikes during periods of geopolitical tension, such as during conflicts involving Ukraine and Russia, indicating a possible alignment with broader political motivations.

IOC Patterns

  • Use of DDoS botnets
  • Phishing emails with malicious links or attachments
  • Unusual network traffic patterns
  • Exfiltration of large data volumes from targeted networks

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts.
  • Harden network infrastructure against DDoS attacks using techniques like load balancing and traffic scrubbing.
  • Conduct regular backups and ensure recovery processes are robust in case of data breaches.
  • Monitor dark web activity for signs of leaked organizational data or threats from NB65.

Suggested Tags

Hacktivism
Political Motivation
Energy Sector
Russia-focused

Confidence Assessment

Low confidence due to limited specific TTPs and tools associated with NB65. Additional intelligence on their attack patterns, toolset, and campaign specifics would enhance this analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Hacktivism
Political Motivation
Energy Sector
Russia-focused

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.