KillNetKillnet CollectiveBlack SkillsWe Are Killnet
Attribution
Pro-Russia hacktivist collective; not formally attributed to a Russian state agency, though multiple vendors assess ideological and probable indirect ties to Russian interests. Anonymous Sudan, publicly aligned with Killnet in 2023, is assessed by several researchers to likely be a Russia-linked front rather than a genuine Sudanese group.
Origin
Russia
First seen
2022-01
Last active
2024
Motivation
Ideological/nationalist hacktivism and political signaling in support of Russia; disruption and psychological effect against NATO, Ukraine-aligned and Western targets, with later attempts at financial/reputational monetization via a 'private military hacking company' brand.
Attribution confidence
medium
MENA targeting
Israel
Sectors
Government
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Israel (Government sector).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
←2023 State of The Threat – A Year in ReviewreportORKL2023-09-29
←2023-05-30 - Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ GoalsreportORKL2023-06-04
Uses
→Acquire Infrastructure: Web ServicestechniqueATT&CK mapping
→Endpoint Denial of Service: Service Exhaustion FloodtechniqueATT&CK mapping
→
Diamond Model
The four features of this adversary's intrusions under the Diamond Model — adversary, capability, infrastructure, victim — assembled from tracked data; pivot from any vertex to the others.
Adversary5
Who is behind the activity — operator vs. customer.
KillnetKillNetKillnet CollectiveBlack SkillsWe Are Killnet
Capability9
Tradecraft, techniques, and tooling the adversary employs.
Physical/logical infrastructure used to deliver capability (C2, domains, relays).
No infrastructure indicators correlated in Radar yet.
Victim2
Targeting — sectors and geographies in scope.
GovernmentIsrael
Social-political (intent)Ideological/nationalist hacktivism and political signaling in support of Russia; disruption and psychological effect against NATO, Ukraine-aligned and Western targets, with later attempts at financial/reputational monetization via a 'private military hacking company' brand.
Operator ↔ CustomerOperator (intrusion crew) acting for a Customer (sponsoring interest) — attribution separates the two.
Honesty note
Attribution ≠ confirmation. Killnet is linked here via TTP overlap and shared infrastructure — not confirmed by original-source reporting. Treat this as a working hypothesis, not a settled fact.
The actor's techniques grouped into kill-chain phases — a partial order across phases; techniques within a phase are co-occurring, not sequenced. Export opens in CTID's Attack Flow Builder.
9 techniques across 3 of 7 stages · 2 of 6 pre-objective stages show known tradecraft — each a chance to break the chain before Actions on Objectives.
1Reconnaissance1
T1591
2Weaponization4
T1584.005T1588.002T1583.006T1583.005
3Delivery
4Exploitation
5Installation
6Command & Control
7Actions on Objectives4
T1498.001T1498.002T1499.002T1499.001
Honesty note
Phase groupings reflect ATT&CK tactic classification, not a confirmed operational timeline for Killnet — see the competing-hypotheses breakdown for how confident this attribution really is.