Back to blog

Blog Post

Hacktivist Activity in Russian-Ukraine War Persists

Share on social

Mar 7, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Hacktivist Activity in Russian-Ukraine War Persists

[Ukraine War Hacktivism]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Hacktivist activity linked to the Russia-Ukraine war remains a persistent threat. CyberKnow, which has been monitoring the hacktivist threat since February 2022, has seen the number of active groups drop from over 130 in mid-2024 to around 80. Daily cyberattacks continue, with distributed denial of service (DDoS) attacks remaining the most common tactic. However, there’s been a noticeable rise in claimed ransomware and operational technology attacks.

Pro-Russian groups have been hit hard by internal conflicts and a Telegram exodus that shut down many channels used to coordinate attacks. Noname057(16), one of the most resilient groups, continues its daily DDoS attacks, through a crows-sourced tool called SSoSia, despite losing its main communication channels. Meanwhile, Cyber Army Russia Reborn has yet to resurface after its Telegram account was taken down.

On the Ukrainian side, groups like IT Army Ukraine have remained steadily active, organizing sustained DDoS attacks against Russian targets. These attacks are often aligned with military operations, targeting infrastructure like telecommunications networks in occupied areas to disrupt Russian command and control.

In the past six months, pro-Russian and pro-Palestinian hacktivist groups have begun coordinating attacks, targeting each others adversaries in a show of mutual support.

Russia-Ukraine War Hacktivist Timeline. Source: CyberKnow

Doxxing remains a popular tactic, with pro-Russian groups like JokerDPR exposing personal information of Ukrainian military personnel and foreign fighters. Meanwhile, hacktivist claims of successful ransomware and operational technology attacks raise questions about whether the perception of disruption can be just as impactful as an actual breach, especially with the increased risk and reputational pressure.

Despite the reduction in active groups, the Russia-Ukraine hacktivist landscape remains active. Well-established groups are unlikely to disappear completely and may turn to other geopolitical conflicts. As long as there are global tensions, hacktivist attacks will remain a threat.

Hacktivist Activity in Russian-Ukraine War Persists
Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient