CSIDB logo
Threat actor

Solntsepek

Attribution profile

Type
Nation State
Location
Russia
Known incidents
1 incident
First seen
2024-02-28
Last seen
2024-02-28
Updated
2026-07-17 05:26
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the aliases Solntsepek, T9000, UAC-0014 and GUR, and is described as being located in Russia according to the provided context. Publicly available sources identify the actor as Ukraine’s military intelligence directorate, referred to as HUR or the Defence Intelligence of Ukraine (GUR), indicating a state‑affiliated relationship with the Ukrainian government. This attribution is repeatedly cited in the supplied articles where the actor claims responsibility for operations against Russian entities.

The actor’s targeting focuses on Russian governmental and military‑related infrastructure, including internet service providers, telecom operators, the state tax service, drone control systems, the banking sector and aviation authorities. Reported objectives involve causing disruption—such as taking down websites, destroying cloud storage, paralyzing internet connections and blocking cash withdrawals—and conducting espionage, exemplified by the claimed capture of tax‑service internet traffic and access to classified aviation data. The actor has also left pro‑Ukrainian messages on compromised platforms, indicating an intent to communicate political messages alongside technical impact.

Typical tactics observed in the described operations include infecting servers with malware, destroying databases and backups, eliminating configuration files that sustain critical services and launching distributed denial‑of‑service attacks that overwhelm network resources. The actor regularly compromises both central and regional servers, attacks associated IT contractors such as Office.ed‑it.ru and employs cyber units to conduct coordinated special operations. Notable campaigns cited in the material are the August 2024 assault on Russian internet providers and industrial facilities, the June 2024 disruption affecting 250 000 consumers in occupied Crimea, the July 2024 banking‑system interference that blocked card transactions, the December 2023 tax‑service attack that destroyed thousands of servers and backups and the earlier drone‑control operation that disabled friend‑or‑foe identification systems. Each of these incidents is presented as a distinct, publicly claimed operation of the actor. The actor’s activity is therefore characterized by repeated, state‑backed cyber actions aimed at impairing Russian state functions and gathering intelligence from compromised systems.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB