IT Army of Ukraine
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The IT Army of Ukraine, also known simply as IT Army, is a Ukrainian hacktivist group that emerged following the Russian invasion of Ukraine in 2022. It was formed with the official blessing of the Ukrainian government and arose after calls from Ukrainian vice prime minister Mykhailo Fedorov for volunteers to conduct cyber operations against Russian targets. The group operates primarily through volunteer participants who coordinate actions via Telegram channels where they announce attacks and share tools.
The IT Army’s activities are directed at Russian digital infrastructure across multiple sectors, including transportation, finance, media, energy, and government institutions. Their actions have produced both disruptive effects, such as distributed denial‑of‑service attacks that delayed flights, knocked banking services offline, and interrupted state television broadcasts, and espionage‑type outcomes, including the exfiltration of internal archives from Gazprom and the claimed leak of documents from the Central Bank of Russia. These outcomes demonstrate a dual focus on causing operational disruption and gathering or exposing sensitive information.
Observed tactics, techniques, and procedures rely heavily on volunteer‑driven DDoS campaigns, website defacements, and data exfiltration. The group has claimed to use custom tools to bypass DDoS protections, referenced applications such as Liberator and Death by 1,000 needles (DB1000N), and leveraged simple web‑based tools like a 2048‑style puzzle game to generate traffic. Communication and claim‑making are conducted through Telegram, where they post statements, screenshots, and links to leaked material. Publicly reported operations include a large‑scale DDoS attack on the Russian flight booking system Leonardo in September 2023 that disrupted departures at Moscow’s Sheremetyevo Airport, a December 2022 DDoS campaign that took VTB Bank’s online services offline, a January 2023 intrusion into Gazprom’s internal archive containing over 6,000 files, and a May 2023 breach of the Skolkovo Foundation’s file hosting service and physical servers. These examples illustrate the group’s recurring use of DDoS for service interruption and its capability to infiltrate and exfiltrate data from high‑profile Russian entities. The IT Army remains a volunteer‑based hacktivist collective with clear ties to Ukrainian governmental encouragement, focusing its efforts on Russian targets through a mix of disruption and information‑gathering tactics.
Incidents
Attributed incidents are available to members.
34 incidents