Menu
Browse

Cyber Threat Actor: @squad3o3

Actor Type Location Known Incidents
 Icon
Activist
1 incident
Profile

The threat actor known as @squad3o3 operates within the pro-Ukraine hacktivist ecosystem, participating in cyber campaigns against entities perceived as adversarial to Ukrainian interests. This actor aligns with collectives such as Anonymous and the Ukraine IT Army, focusing on disruptive operations targeting Russian infrastructure and affiliated organizations. Primary objectives center on causing operational interference and logistical degradation rather than financial theft or data exfiltration. Geographically, activities concentrate on Russian assets, with secondary targeting observed in Lithuania during coordinated efforts. Sector priorities include critical infrastructure nodes, government services, military-associated platforms, and media outlets, reflecting a strategy to amplify systemic disruptions and impair public service continuity.

@squad3o3 employs distributed denial-of-service (DDoS) attacks alongside exploitation of misconfigured Docker instances to compromise computational resources. These techniques enable sustained offensive operations by co-opting vulnerable infrastructure for attack staging. A notable May 2022 campaign disrupted a critical Russian alcohol distribution network, causing factory shipment halts and production declines by attacking logistical control systems. Concurrent operations temporarily disabled government, military, and media websites in Russia and Lithuania, leveraging hijacked resources to maintain attack persistence. The actor’s affiliation with broader hacktivist coalitions suggests resource and tactic sharing, though specific command structures or hierarchical relationships remain undocumented in available reporting.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources