CSIDB logo
Threat actor

Russian hacker group

Attribution profile

Type
Undetermined
Location
Russia
Known incidents
1 incident
First seen
2025-02-12
Last seen
2025-02-12
Updated
2026-09-02 14:41
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is publicly referenced as a Russian hacker group and is understood to be based in the Russian Federation. The group entered public awareness after claiming responsibility for a cyber incident that took place on Wednesday, 12 February 2025. On that morning, the Bremen public administration in Germany was hit by a distributed denial‑of‑service campaign that generated as many as eighteen thousand HTTP requests per minute against its web servers. The flood of traffic overwhelmed the city’s online platforms, causing the administrative portal and the police website to become temporarily unavailable to users. In response, the central cybersecurity office within the Senator for Internal Affairs activated mitigation measures and reported that the majority of the malicious traffic was blocked during the morning hours. By evening the attack traffic had diminished, allowing the affected websites to be restored to normal operation. A separately planned system update that was scheduled for the same evening introduced an additional, brief outage, but the administration remained reachable through the 115 citizen hotline and the police continued to be accessible via their central emergency line. After the update was completed, all municipal web services returned to full functionality, and the incident was logged for further examination. Forensic analysts and investigators continue to review logs, network traces, and any associated infrastructure to determine the origin and methods used in the attack. No public release has yet disclosed specific malware families, exploit tools, or initial‑access vectors linked to this operation.

The observed activity shows that, at least in this instance, the group focused on a German municipal government body and sought to disrupt the availability of its public‑facing online services. Because no technical details were disclosed in the reporting, the group’s preferred malware families, exploit frameworks, or credential‑theft techniques remain unspecified in open sources. Attribution to a Russian hacker group rests on the actors’ own claim of responsibility; no independent evidence has been presented that ties the group to a state sponsor or to a broader criminal alliance. The Bremen denial‑of‑service event constitutes the only publicly documented operation associated with this alias, offering the sole concrete illustration of their operational pattern to date. Ongoing work by German authorities includes tracing command‑and‑control infrastructure, assessing any potential collateral impact, and determining whether similar tactics might be employed in future incidents. Until further technical information is released, the profile of this threat actor is limited to the confirmed facts of the February 2025 attack on Bremen’s public administration.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB