Main Intelligence Directorate of Ukraine's Defense Ministry (HUR)
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Main Intelligence Directorate of Ukraine's Defense Ministry, commonly referred to by its acronym HUR, is a state‑run intelligence organization based in Ukraine. As a constituent part of Ukraine's defense apparatus, HUR operates under governmental authority and is publicly recognized as a Ukrainian state actor. The only publicly documented activity attributed to HUR in the available source material is a cyber operation conducted on 24 January 2025 against a major Russian telecommunications provider. This operation targeted the operator's network and caused service degradation for the company itself as well as for downstream providers such as Yota and NetByNet. The disruption extended to mobile and internet connectivity in major Russian cities including Moscow and Saint Petersburg, as well as several central regions, and temporarily blocked access to platforms like Steam, Twitch and Discord that are reportedly used by Russian military and intelligence personnel. Russian officials characterized the incident as a successful carpet DDoS attack, indicating that the primary objective of the action was to disrupt communications and online services.
The tactics observed in the January 2025 incident align with a distributed denial‑of‑service approach, specifically described as a carpet DDoS attack that overwhelms target infrastructure with voluminous traffic from multiple sources. No specific malware families, initial‑access vectors, or bespoke tooling are mentioned in the reporting, so the only confirmed TTP theme for HUR in the open source record is the use of large‑scale DDoS flooding to achieve service interruption. The attack's effects were corroborated by Russia's communications watchdog, Roskomnadzor, which acknowledged the network disruption, while the targeted operator publicly maintained that its core network remained functional and attributed user‑experience problems to unrelated causes. Because the source material provides no further operations or technical details, any broader pattern of behavior, toolset, or recurring targeting cannot be derived from the available information. Consequently, the profile of HUR remains limited to this single, publicly reported disruptive cyber action against a Russian telecom entity.
Incidents
Attributed incidents are available to members.
1 incident