Menu
Browse

Cyber Threat Actor: Cyber Corps

Updated 2026-08-17 06:55
Actor Type Location Known Incidents
 Icon
Activist
Ukraine
1 incident
Characteristics
Threat actor characteristics available to members
Profile

Cyber Corps is the alias used for a Ukrainian cyber specialist group. Open‑source references locate the actor’s base of operations in Ukraine. No additional aliases or alternative names have been attributed to the group in public reporting. The actor is described as a collection of individuals conducting cyber activities rather than a registered organization. Beyond its geographic origin, no further structural details such as size, funding, or hierarchical organization have been disclosed.

On 10 August 2026, Cyber Corps carried out an operation against the Russian marketplace Wildberries. The operation specifically targeted the platform’s customer service channel and its payment systems. By interfering with these services, the attackers disrupted the marketplace’s digital infrastructure. Users were unable to complete financial transactions, leading to a noticeable drop in successful payments. The disruption generated a surge of user complaints, which in turn increased the workload on Wildberries’ contact centers and support teams. Technical reports from the incident indicate that the attack caused widespread service degradation across the site. No public disclosure has identified the specific malware, exploit kits, or initial access vectors used in the operation. The effects were limited to service availability and user experience, with no reported data theft or extortion demands.

Based on the Wildberries incident, the actor’s known targeting includes e‑commerce platforms operating in the Russian market. The observed impact consisted of disrupted customer service and payment functions, leading to failed transactions and heightened support demand. No details regarding malware families, custom tooling, or preferred initial access vectors have been released in connection with this activity. Attribution to a state sponsor or criminal consortium has not been established in any public source; the actor is only linked to its Ukrainian origin. Consequently, the group’s broader campaign history, typical tooling style, or recurring patterns remain undocumented beyond the single reported operation. Analysts therefore rely exclusively on the confirmed Wildberries action when describing Cyber Corps’ capabilities and behavior. No further publicly attributed incidents have been linked to the alias as of the latest available information. This profile reflects only the facts that have been explicitly reported and avoids speculation about undisclosed aspects of the actor.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources