New publication. Cadet Blizzard.

Cadet Blizzard: When Cyber Espionage Becomes Cyber Sabotage

Some threat actors steal information. Others are built to disrupt, destroy, and support broader military objectives.

Cadet Blizzard (also tracked as Ember Bear and DEV-0586) belongs to the latter category. Widely linked by leading cybersecurity organisations to GRU Unit 29155, the group has become one of the key Russian cyber actors targeting Ukraine, NATO members, and organisations supporting Ukraine.

[Read more]

New publication. KillNet.

Our latest OSINT report focuses on KillNet.

KillNet has evolved far beyond a conventional hacktivist group. Our analysis shows that its campaigns consistently align with political developments and the geopolitical interests of the Russian Federation, while technical attacks are regularly combined with coordinated information and psychological operations.

Although most of its operations rely on relatively low-complexity techniques, KillNet remains one of the most influential pro-Russian cyber groups due to its ability to rapidly mobilize a broad network of supporters, coordinate large-scale DDoS campaigns, and amplify their impact through Telegram and other online platforms.

[Read more]

New publication. Ghostwriter (UNC1151).

Ghostwriter (UNC1151) has become one of the most closely tracked threat actors operating against Ukraine, NATO members, and Eastern European governments.

Over nearly a decade of activity, the group has combined credential harvesting, malware deployment, website compromises, cyber espionage, and coordinated influence operations targeting government institutions, military personnel, journalists, media organizations, and political actors. Public reporting has linked Ghostwriter to Belarusian military intelligence, while multiple government assessments and threat intelligence investigations have also pointed to coordination with Russian military structures and broader geopolitical objectives.

[Read more]

New publication. Dragonfly.

Dragonfly is one of the most well-known Russian APT groups, which for years has focused its operations on the energy sector and industrial control systems.

In this report, we examine the group’s history, tooling, known operations, and reported links to Russian state structures. Particular attention is given to campaigns targeting U.S. energy companies, including the attack on Wolf Creek Nuclear Operating Corporation.

[Read more]

New publication. NoName057(16).

NoName057(16) is a pro-russian hacktivist collective that has been conducting large-scale DDoS campaigns against government institutions, financial systems, transportation infrastructure, and media organizations across Europe and NATO-aligned countries since 2022. Unlike traditional APT groups, its activities are not focused on espionage or long-term persistence, but rather on disruption and the degradation of digital services.

[Read more]

Приватний розділ

Для доступу до приватного розділу введіть пароль:

Materials

Page 1 of 1
Page 1 of 1