UserSec
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
UserSec is a pro‑Russia hacking group that operates under the alias UserSec and is based in Russia. The group has been described in open sources as affiliated with the hacking collective Anonymous Russia, indicating a loose cooperative relationship with other Russian‑aligned actors. UserSec presents itself as ideologically motivated, aligning its activities with pro‑Russian narratives, and it has claimed responsibility for several disruptive actions against United Kingdom targets.
The group’s known activities focus on causing disruption to online services, particularly through distributed denial of service (DDoS) attacks that overwhelm websites and render them temporarily inaccessible. UserSec has announced a coordinated campaign targeting UK airport websites, asserting that it aims to disrupt the digital presence of these facilities as part of a broader political statement. While the group’s statements suggest a desire to create visible impact, the actual operational consequences have been limited to website outages, with flight operations and passenger services reported to remain unaffected during the incidents.
In terms of tactics, the only technique explicitly attributed to UserSec in the reporting is the execution of DDoS floods that saturate web servers until the sites become unavailable. No specific malware families, initial access vectors, or custom tooling have been disclosed in the available sources, so the group’s technical profile remains defined by its use of volumetric traffic‑based disruption.
Representative operations claimed by UserSec include the October 2023 outage of Manchester Airport’s website, which the group said was part of its announced series of attacks on UK airports, and the July 2023 disruption of London City Airport’s site, which coincided with a claim of responsibility and was described as part of the same coordinated effort. In both cases the airports confirmed that the websites were restored sooner than the attackers’ stated deadlines, and investigations were undertaken by the airports’ IT teams and the UK National Cyber Security Centre. These incidents illustrate UserSec’s reliance on DDoS‑style disruption to achieve its proclaimed objectives.
Incidents
Attributed incidents are available to members.
2 incidents