Solntsepek is a threat actor group with ties to the Russian military unit GRU. They have claimed responsibility for a cyberattack on Kyivstar, a Ukrainian mobile operator, and have been linked to previous attacks on Ukrainian infrastructure. Solntsepek has been associated with the Sandworm hacking group, known for their destructive cyberattacks, including the NotPetya worm. They have also engaged in hostile activities, such as revealing personal details of Ukrainian soldiers.
Executive Summary
Solntsepek is a state-sponsored cyber threat group linked to the Russian GRU, known for targeting Ukrainian infrastructure with destructive attacks such as NotPetya. Their activities include phishing, credential harvesting, and DDoS campaigns, posing significant risks to critical sectors in Ukraine.
Goals & Targeting
Solntsepek's strategic objectives appear to align with broader Russian interests in destabilizing Ukraine. Their targeting focuses on sectors critical to national defense and public stability, such as telecommunications and energy infrastructure. The group likely aims to achieve political influence, demonstrate military capabilities, and sow discord within Ukrainian society through disruptive cyber activities.
Enhanced Description
Solntsepek operates with high sophistication, leveraging advanced persistent threat (APT) tactics similar to the Sandworm group. They primarily target Ukrainian critical infrastructure, including energy grids and mobile operators, with the goal of disrupting services and creating instability. Their activities demonstrate a clear political motive aligned with Russian interests in Ukraine. The group's history includes exposing personal data of military personnel, indicating both offensive cyber capabilities and a focus on undermining national security.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Solntsepek has conducted multiple campaigns targeting Ukrainian infrastructure, including the attack on Kyivstar. Their methods involve long-term infiltration using APT tactics to gather intelligence and disrupt operations. Notable activities include data exposure of military personnel and disruptive attacks post-elections in Ukraine.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Solntsepek's links to GRU and Sandworm, but limited direct reporting on their specific TTPs. Gaps include exact toolset and more detailed attack patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics