Back to blog

Blog Post

Hacktivist Activity in Russian-Ukraine War Persists

Share on social

Mar 7, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Hacktivist Activity in Russian-Ukraine War Persists

[Ukraine War Hacktivism]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Hacktivist activity linked to the Russia-Ukraine war remains a persistent threat. CyberKnow, which has been monitoring the hacktivist threat since February 2022, has seen the number of active groups drop from over 130 in mid-2024 to around 80. Daily cyberattacks continue, with distributed denial of service (DDoS) attacks remaining the most common tactic. However, there’s been a noticeable rise in claimed ransomware and operational technology attacks.

Pro-Russian groups have been hit hard by internal conflicts and a Telegram exodus that shut down many channels used to coordinate attacks. Noname057(16), one of the most resilient groups, continues its daily DDoS attacks, through a crows-sourced tool called SSoSia, despite losing its main communication channels. Meanwhile, Cyber Army Russia Reborn has yet to resurface after its Telegram account was taken down.

On the Ukrainian side, groups like IT Army Ukraine have remained steadily active, organizing sustained DDoS attacks against Russian targets. These attacks are often aligned with military operations, targeting infrastructure like telecommunications networks in occupied areas to disrupt Russian command and control.

In the past six months, pro-Russian and pro-Palestinian hacktivist groups have begun coordinating attacks, targeting each others adversaries in a show of mutual support.

Russia-Ukraine War Hacktivist Timeline. Source: CyberKnow

Doxxing remains a popular tactic, with pro-Russian groups like JokerDPR exposing personal information of Ukrainian military personnel and foreign fighters. Meanwhile, hacktivist claims of successful ransomware and operational technology attacks raise questions about whether the perception of disruption can be just as impactful as an actual breach, especially with the increased risk and reputational pressure.

Despite the reduction in active groups, the Russia-Ukraine hacktivist landscape remains active. Well-established groups are unlikely to disappear completely and may turn to other geopolitical conflicts. As long as there are global tensions, hacktivist attacks will remain a threat.

Hacktivist Activity in Russian-Ukraine War Persists
Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient