Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Solntsepek

Description

Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobile operator, and have been linked to previous attacks on Ukrainian infrastructure. Solntsepek has been associated with the Sandworm hacking group, known for their destructive cyberattacks, including the NotPetya worm. They have also engaged in hostile activities, such as revealing personal details of Ukrainian soldiers.

AI Analysis

· 1 week ago

Executive Summary

Solntsepek is a state-sponsored cyber threat group linked to the Russian GRU, known for targeting Ukrainian infrastructure with destructive attacks such as NotPetya. Their activities include phishing, credential harvesting, and DDoS campaigns, posing significant risks to critical sectors in Ukraine.

Goals & Targeting

Solntsepek's strategic objectives appear to align with broader Russian interests in destabilizing Ukraine. Their targeting focuses on sectors critical to national defense and public stability, such as telecommunications and energy infrastructure. The group likely aims to achieve political influence, demonstrate military capabilities, and sow discord within Ukrainian society through disruptive cyber activities.

Enhanced Description

Solntsepek operates with high sophistication, leveraging advanced persistent threat (APT) tactics similar to the Sandworm group. They primarily target Ukrainian critical infrastructure, including energy grids and mobile operators, with the goal of disrupting services and creating instability. Their activities demonstrate a clear political motive aligned with Russian interests in Ukraine. The group's history includes exposing personal data of military personnel, indicating both offensive cyber capabilities and a focus on undermining national security.

Key Capabilities

  • Advanced persistent threat (APT) campaigns
  • Destructive malware deployment
  • Spear-phishing attacks
  • Credential harvesting via keyloggers
  • Disinformation campaigns

MITRE ATT&CK Tactics

Initial Access
Defense Evasion

ATT&CK Techniques

T1505
T1562.004

Software / Tooling

Custom C2 Frameworks
Phishing Email Templates
Destructive Malware

Campaigns & Victims

Solntsepek has conducted multiple campaigns targeting Ukrainian infrastructure, including the attack on Kyivstar. Their methods involve long-term infiltration using APT tactics to gather intelligence and disrupt operations. Notable activities include data exposure of military personnel and disruptive attacks post-elections in Ukraine.

IOC Patterns

  • Large-scale DDoS traffic originating from Eastern Europe
  • Phishing emails mimicking government officials or IT support teams
  • Malicious scripts dropped via spear-phishing campaigns

Recommended Actions

  • Implement network monitoring for异常traffic patterns linked to DDoS and APT activities.
  • Adopt email filtering solutions with AI/ML capabilities to detect phishing attempts.
  • Enforce multi-factor authentication for critical systems.
  • Regularly back up critical infrastructure against potential destructive attacks.

Suggested Tags

APT
State-Sponsored
Cyber Espionage
Critical Infrastructure

Confidence Assessment

Moderate confidence in Solntsepek's links to GRU and Sandworm, but limited direct reporting on their specific TTPs. Gaps include exact toolset and more detailed attack patterns.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Government Targeting
Wiper / Destructive
APT
State-Sponsored
Cyber Espionage
Critical Infrastructure

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.