CSIDB logo
Threat actor

Cyber.Anarchy.Squad

Attribution profile

Type
Activist
Location
Ukraine
Known incidents
2 incidents
First seen
2023-06-08
Last seen
2024-06-29
Updated
2026-07-30 23:48
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Cyber.Anarchy.Squad is a pro‑Ukrainian hacker group that operates under the alias Cyber.Anarchy.Squad and is known to be based in Ukraine. The group first gained public attention after Russia’s invasion of Ukraine, positioning itself as a hacktivist actor conducting cyber operations against Russian targets. It has claimed responsibility for several high‑profile incidents and has been referenced in multiple security reports detailing its activities. The group’s public communications typically appear on Telegram channels where it shares proof of access and leaked data.

The actor’s targeting has been consistently directed at Russian organizations across several sectors, including telecommunications, cybersecurity services, retail, and jewelry manufacturing. Its operations are aimed at causing disruption of services, as evidenced by the destruction of network equipment that severed connectivity between the Russian Central Bank and financial institutions, and by encrypting virtual machines and workstations to render systems unusable. In addition to disruption, the group seeks to expose sensitive information, having leaked large volumes of data allegedly taken from breached networks and published the material via Telegram and Mega file‑sharing services. These objectives are explicitly stated in the group’s own announcements and the affected companies’ confirmations.

Observed tactics, techniques, and procedures include the use of encryption to lock virtual machines and physical workstations, the deliberate damage of network hardware to induce outages, and the exfiltration of data for public leakage. The group has shared screenshots of network diagrams and compromised email accounts as proof of intrusion, and it has distributed stolen databases through Telegram and Mega. No specific malware families or initial access vectors are described in the available sources, so the profile is limited to these confirmed behaviors. The group’s tooling style appears to focus on rapid data publication and destruction rather than prolonged stealth or espionage‑grade persistence.

Attribution to a state sponsor or criminal consortium has not been established in public reporting; the group is described as a hacktivist collective acting in support of Ukraine. Notable campaigns referenced in the sources include the June 2023 attack on Russian telecom provider Infotel JSC that disrupted banking connectivity, the June 2024 assault on cybersecurity firm Avanpost that encrypted hundreds of systems and leaked terabytes of data, and earlier operations that exposed millions of records from a Russian retailer and a jewelry manufacturer. These incidents illustrate the group’s pattern of targeting Russian entities to cause service interruption and to disseminate allegedly sensitive information.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB