CSIDB logo
Threat actor

Ukrainian Cyber Alliance

Attribution profile

Type
Activist
Location
Ukraine
Known incidents
4 incidents
First seen
2014-02-28
Last seen
2025-01-07
Updated
2026-08-01 06:15
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Anonymous Ukraine is a hacktivist group that publicly identifies itself as the Patriots of Ukraine and uses the moniker Anonymous Ukraine; the group has also been referred to in reporting as Cyber Hunta. Members describe themselves as part of the broader Anonymous collective and frame their actions as patriotic efforts to defend Ukrainian sovereignty and independence. They have issued statements proclaiming that they do not forgive or forget and that they will continue operations under the banner of #OpIndependence.

The group’s targeting, as described in open sources, focuses on governmental and political entities perceived as threatening Ukrainian integrity. They have compromised the email account of an assistant to Russian presidential aide Vladislav Surkov, leaking more than two thousand messages that included casualty lists from the separatist Donetsk People’s Republic and expense records for the separatist Ministry of Information. They also accessed the email account of Laurynas Jonavicius, an adviser to the President of Lithuania, and the correspondence of Vitali Klitschko’s Ukrainian Democratic Alliance for Reform (UDAR) party. In their public messages the actors state that they aim to expose corruption, reveal ties between Western actors and Ukrainian figures, disclose separatist activities, and oppose what they describe as Western hirelings and fascists seeking to destabilize Ukraine, while advocating for a unified and independent state.

Their observed tactics involve gaining unauthorized access to email accounts, exfiltrating the contents, and distributing the material through publicly available file‑sharing services such as MediaFire, FileFactory, 4shared and Sendspace, with links shared on Pastebin pastes. The sources do not reference specific malware families, exploit kits, or custom tools; the described activity centers on credential harvesting and data leakage rather than the deployment of malicious code. Attribution claims made by the group are limited to their self‑identification as Ukrainian patriots; no governmental sponsorship is asserted in the material. Analysts have speculated that the Surkov leak could be a retaliatory measure, but this remains commentary rather than established fact.

Notable operations attributed to the group include the Cyber Hunta intrusion into the Surkov aide’s account, which yielded the DNR casualty list and Ministry of Information expense documents, the Anonymous Ukraine breach of the Lithuanian adviser’s email and the UDAR party’s internal communications, and the broader #OpIndependence campaign that targeted perceived Western influence and fascist elements while promoting Ukrainian unity. These actions illustrate the group’s focus on information disclosure as a means to advance its stated political objectives.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB