Killnet is a loose pro-Russia hacktivist collective that emerged around Russia's February 2022 invasion of Ukraine, best known for volumetric DDoS attacks used as political signaling against government, transport, healthcare, and financial websites in NATO and Ukraine-aligned countries. Founded and long fronted by a persona known as 'Killmilk', it operated as a decentralized umbrella of subgroups (e.g. ZARYA, Anonymous Russia, Phoenix, Legion) and affiliates rather than a disciplined intrusion team. Its impact was mostly short-lived service disruption and propaganda amplification; hack-and-leak and 'breach' claims were frequently exaggerated or unverified. By 2023-2024 the group rebranded toward a commercial 'private military hacking company' (Black Skills) before activity and cohesion visibly declined.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Killnet appeared in early 2022, initially advertising a DDoS-for-hire booter service before pivoting to overtly pro-Russia hacktivism after the invasion of Ukraine. Through 2022 it ran waves of DDoS campaigns framed as retaliation against countries supporting Ukraine, hitting government portals, airports, banks, and healthcare sites in Romania, Italy, Lithuania, Estonia, the United States, and others. These operations were technically unsophisticated (Layer 3/4 and Layer 7 flooding, often leveraging rented infrastructure and volunteer tooling) and their primary value was psychological and informational rather than access or destruction. Vendors including Mandiant/Google, Microsoft, Radware, Flashpoint, and CISA characterized Killnet as a signaling and influence instrument: attacks were loudly pre-announced and self-promoted on Telegram to project reach disproportionate to actual effect.
The collective was organizationally fluid. Killmilk announced stepping back from day-to-day leadership in mid-2022 and the brand persisted as an umbrella coordinating semi-independent subgroups and allied crews. In February 2023 Anonymous Sudan publicly aligned with Killnet and became its most prolific DDoS affiliate; multiple analysts (e.g. Trustwave/CyberCX reporting cited widely) assessed Anonymous Sudan's Islamist-Sudanese framing to be a likely cover for a Russia-linked operation given its infrastructure, targeting, and coordination with Killnet. In March 2023 Killmilk announced 'Black Skills', explicitly styled as a Private Military Hacking Company and compared to Wagner; Recorded Future and others assessed this as aspirational branding and monetization theater more than a realized capability. Killnet also dabbled in selling services, 'DDoS courses', and reputation-driven extortion, but never demonstrated durable intrusion, espionage, or reliable data-theft tradecraft. Hack-and-leak claims (alleged breaches of Western agencies, Lockheed Martin data, etc.) were routinely overstated and often recycled or unverifiable. Activity and public cohesion declined notably through 2024 amid leadership drama, infighting, and the fading novelty of the DDoS-signaling model, leaving the group best described as dormant with an intermittent Telegram presence rather than defunct.
MENA relevance: Thin and claim-based. Killnet's connection to the MENA region runs mainly through Anonymous Sudan, its 2023 affiliate, and through episodic anti-Israel DDoS claims. During 2023 (and around the October 2023 Israel-Hamas escalation) Killnet and aligned crews publicly claimed DDoS attacks on Israeli websites, but these were self-reported, short-duration disruptions with little independent technical corroboration and no verified breach or data theft against Israeli targets. The existing RaqibCTI 'Israel' country tag is therefore UNVERIFIED/claim-based signaling activity, not confirmed impactful targeting — it should be retained only with an explicit low-confidence, 'claimed DDoS' qualifier rather than treated as an established operational campaign.