CSIDB logo
Threat actor

OneFist

Attribution profile

Type
Activist
Location
Ukraine
Known incidents
1 incident
First seen
2022-09-28
Last seen
2022-09-28
Updated
2026-07-30 18:29
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

OneFist is a hacker group known by the alias OneFist and has been associated with Ukraine. The group claims to be affiliated with Ukraine’s IT Army, a pro‑Ukraine hacktivist collective. Public sources locate the group’s activity within Ukraine, though no further geographic details are provided. The alias appears in reporting related to operations against Russian infrastructure.

OneFist’s targeting has been observed against Russian satellite communications services, specifically the Gonets low Earth orbit network. The victims include commercial fishing and logistics firms as well as Russian government entities such as regional offices of the Federal Security Service and missile or space technology organizations. The group’s stated objective in the reported operation was to disrupt the satellite network’s ability to authenticate and bill users, thereby impairing messaging services. No explicit mention of financial gain or espionage motives appears in the source material.

The group’s tactics, as described in the incident, involve exploiting a misconfiguration in the victim’s customer relationship management system that allowed the attackers to log in as legitimate users. After gaining access, they did not attempt privilege escalation but instead deleted the CRM database, which was essential for the satellite system’s authentication and billing functions. No malware families or custom tooling are referenced in the reporting; the attackers relied on legitimate credentials and the inherent design flaw of the exposed CRM. Their approach highlights a focus on configuration weaknesses rather than malicious code deployment.

The most publicly documented operation attributed to OneFist occurred on September 28, 2022, when the group breached the Gonets satellite network’s CRM and erased its database of 97 client accounts. This action crippled the network’s ability to verify active accounts and process bills, effectively disabling the satellite messaging service. The incident was linked to broader pro‑Ukraine efforts to target Russian infrastructure during the ongoing conflict. No other campaigns are detailed in the provided sources.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB